MdRes.exe

  • File Path: C:\WINDOWS\system32\MdRes.exe
  • Description: Windows Memory Diagnostic

Hashes

Type Hash
MD5 B6758BBCC043C43EF5B0D04E1016C245
SHA1 DAD03EE4EE71A612875897C96131FFF261C70B8A
SHA256 DC751AC0E1397BDCCA9A4DD4FD9D21C1AAA79C8DBB60B0A548F5569F10551175
SHA384 CC3DCE906BA4D12E2EA16739B750821A4D794314ED18FE6CBAE5F0EDA63604652A98BC22CFFB976D23BEF1C77E51E62B
SHA512 2D4BA4252A4F14A64D2B4319FB4E5CAD4EB3FD920A2659ECC6BF142DC1F4FAE4BD8D188459A912808F65574FCEFD11731B50E41BE9A6E10AFF1B2843F5CF885F
SSDEEP 1536:Z72O4eHOHsm+65tFI720+VpmDOzc4JNWxwB1MjVJmRc:Z7/Mse/FO+VQDUcUNWs+jm6
IMP 3D553FEF2350214DF4679F35FF59A173
PESHA1 72BF97C313AAC88E70915E2BA61C79E495F54A3F
PE256 BB12BF54826406ABA1A031C61F313D5ED21DCBB2E5442858DA90D52E12E4636D

Runtime Data

Loaded Modules:

Path
C:\WINDOWS\System32\ADVAPI32.dll
C:\WINDOWS\System32\KERNEL32.DLL
C:\WINDOWS\System32\KERNELBASE.dll
C:\WINDOWS\system32\MdRes.exe
C:\WINDOWS\System32\msvcrt.dll
C:\WINDOWS\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: MdRes.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.22000.1 (WinBuild.160101.0800)
  • Product Version: 10.0.22000.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/dc751ac0e1397bdcca9a4dd4fd9d21c1aaa79c8dbb60b0a548f5569f10551175/detection

File Similarity (ssdeep match)

File Score
C:\Windows\system32\MdRes.exe 82
C:\WINDOWS\system32\MdRes.exe 83
C:\Windows\system32\MdRes.exe 86
C:\windows\system32\MdRes.exe 80
C:\Windows\system32\MdRes.exe 83
C:\Windows\system32\MdSched.exe 79
C:\windows\system32\MdSched.exe 79
C:\Windows\system32\MdSched.exe 80
C:\Windows\system32\MdSched.exe 79
C:\WINDOWS\system32\MdSched.exe 79
C:\WINDOWS\system32\MdSched.exe 79

MIT License. Copyright (c) 2020-2021 Strontic.