IMCCPHR.exe
- File Path:
C:\WINDOWS\system32\IME\SHARED\IMCCPHR.exe
- Description: IMCCPHR.exe
Screenshot
Hashes
Type |
Hash |
MD5 |
9DAE16C2851477678288ECDC7A387B0A |
SHA1 |
FFC82E532C2371D5DE9097603990959D824412A5 |
SHA256 |
E0F346692AE5EC6BAA668B88C1279ED950EE1B53B49E14FEE030A739E84A7A85 |
SHA384 |
5CF9E78447EF9EE9975676C6370181E3FCE59CF7155917C407B90FEA9ECDB17386858F4C7E7060B0B91F496762CABE79 |
SHA512 |
8E131A1333CA39EF4FD73A3B8E67065CCA4A24520607CFD01BF74E5D2373FBB6579197D3A62633B13119DF33B11219878EF1359CA788C9AC3D2D619108DFD5A9 |
SSDEEP |
6144:RhH2q9ypYEjK/JUNVmsLW/yaOlx8uSXmCPwP6k+kc8DZ5n:/HD9yCEiDsSfuSXmH6k+kcuv |
IMP |
4321F2EDB359F35D8333BD4331CF3981 |
PESHA1 |
9B24E8B81B88BEC4C77F6A0215B5D3F16DEA0719 |
PE256 |
3474639CD743BB90BF62BF5CF5ED42BDC51743EC32A5E14BB66E30AB66573D43 |
Runtime Data
Window Title:
User-defined Phrase Tool for Microsoft Pinyin IME
Open Handles:
Path |
Type |
(R-D) C:\Windows\Fonts\StaticCache.dat |
File |
(R-D) C:\Windows\SystemResources\imageres.dll.mun |
File |
(RW-) C:\Windows\System32 |
File |
(RW-) C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.22000.120_none_9d947278b86cc467 |
File |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000001.db |
Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db |
Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro |
Section |
\Sessions\2\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 |
Section |
\Sessions\2\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 |
Section |
\Sessions\2\Windows\Theme1077709572 |
Section |
\Windows\Theme3461253685 |
Section |
Loaded Modules:
Path |
C:\WINDOWS\system32\IME\SHARED\IMCCPHR.exe |
C:\WINDOWS\System32\KERNEL32.DLL |
C:\WINDOWS\System32\KERNELBASE.dll |
C:\WINDOWS\SYSTEM32\ntdll.dll |
Signature
- Status: Signature verified.
- Serial:
33000002ED2C45E4C145CF48440000000002ED
- Thumbprint:
312860D2047EB81F8F58C29FF19ECDB4C634CF6A
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Original Filename: IMCCPHR.exe
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.22000.1 (WinBuild.160101.0800)
- Product Version: 10.0.22000.1
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 64-bit
File Scan
- VirusTotal Detections: Unknown
File Similarity (ssdeep match)
MIT License. Copyright (c) 2020-2021 Strontic.