Bginfo64.exe

  • File Path: C:\SysinternalsSuite\Bginfo64.exe
  • Description: BGInfo - Wallpaper text configurator

Screenshot

Bginfo64.exe Bginfo64.exe

Hashes

Type Hash
MD5 6C86343A7D4BF2C7B938AC5AB35F12E5
SHA1 D1D624793DF89E1AA085C514F922A96999AC108C
SHA256 99CBD0CE2A5FDEF88F41B47BA07786C641D582D8A0800F39618799AD1425DF82
SHA384 672910AE9145CC5E7E727D582D2095659BBDC3516FEFDECA46C7B480246B777FA97300BA43B7D45F10C9985A3CE8DF32
SHA512 BC3CCB0CBEB44C32A130DD0453E4A2F88A1F1836958A126CFA77D122BB7CAEB3D2215E1EC27164CF51A68E7CD49B66DB363EB1760D2AA883E3397C72B2870882
SSDEEP 49152:mWAmpnH43anE3lvu6bkQkUkvlgrnPVnPGJ5NGD24XKfSxXnW6l2nTM:jO37zElg79ANs1KfQ3t0TM
IMP 7678BEC9F0282BACD5BA9B6AA227FDAE
PESHA1 8C1B8220C92488B92885C1031640F55278122CAF
PE256 078D5C1C46CF44C4113AB2D3D40F93EA5D9617E71B86DA7FF8292C328207FB2D

Runtime Data

Window Title:

BGInfo

Open Handles:

Path Type
(R-D) C:\Windows\Fonts\StaticCache.dat File
(R-D) C:\Windows\System32\en-US\user32.dll.mui File
(R-D) C:\Windows\SystemResources\imageres.dll.mun File
(RW-) C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21 File
(RW-) C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.508_none_faefa4f37613d18e File
(RW-) C:\xCyclopedia File
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\Sessions\1\Windows\Theme2036293991 Section
\Windows\Theme1324212991 Section

Loaded Modules:

Path
C:\SysinternalsSuite\Bginfo64.exe
C:\Windows\System32\ADVAPI32.dll
C:\Windows\System32\combase.dll
C:\Windows\System32\COMDLG32.dll
C:\Windows\System32\CRYPT32.dll
C:\Windows\SYSTEM32\DPAPI.DLL
C:\Windows\System32\GDI32.dll
C:\Windows\System32\gdi32full.dll
C:\Windows\System32\IMM32.dll
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\MSIMG32.dll
C:\Windows\System32\msvcp_win.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\NETAPI32.dll
C:\Windows\SYSTEM32\NETUTILS.DLL
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\SYSTEM32\ODBC32.dll
C:\Windows\System32\ole32.dll
C:\Windows\SYSTEM32\OLEACC.dll
C:\Windows\System32\OLEAUT32.dll
C:\Windows\SYSTEM32\oledlg.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\sechost.dll
C:\Windows\System32\shcore.dll
C:\Windows\System32\SHELL32.dll
C:\Windows\System32\SHLWAPI.dll
C:\Windows\SYSTEM32\snmpapi.dll
C:\Windows\SYSTEM32\SRVCLI.DLL
C:\Windows\System32\ucrtbase.dll
C:\Windows\System32\USER32.dll
C:\Windows\SYSTEM32\UxTheme.dll
C:\Windows\SYSTEM32\VERSION.dll
C:\Windows\System32\win32u.dll
C:\Windows\SYSTEM32\WINMM.dll
C:\Windows\SYSTEM32\WINSPOOL.DRV
C:\Windows\SYSTEM32\WKSCLI.DLL
C:\Windows\System32\WS2_32.dll
C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\COMCTL32.dll
C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.508_none_faefa4f37613d18e\gdiplus.dll

Signature

  • Status: Signature verified.
  • Serial: 33000001519E8D8F4071A30E41000000000151
  • Thumbprint: 62009AAABDAE749FD47D19150958329BF6FF4B34
  • Issuer: CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: BGInfo.exe
  • Product Name: BGInfo
  • Company Name: Sysinternals - www.sysinternals.com
  • File Version: 4.28
  • Product Version: 4.28
  • Language: English (United States)
  • Legal Copyright: Copyright 2000-2019 Mark Russinovich
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/66
  • VirusTotal Link: https://www.virustotal.com/gui/file/99cbd0ce2a5fdef88f41b47ba07786c641d582d8a0800f39618799ad1425df82/detection/

Possible Misuse

The following table contains possible examples of Bginfo64.exe being misused. While Bginfo64.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_false_sysinternalsuite.yml - '\Bginfo64.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.