MdSched.exe

  • File Path: C:\Windows\system32\MdSched.exe
  • Description: Windows Memory Diagnostics Tool

Hashes

Type Hash
MD5 26F5DBA1FB3B8E477BF3941879B23E59
SHA1 B16FE1174F84B5B04A865C0E1200EFC486DF7D0F
SHA256 BC516F17AFC7658C4F20726272D9CE9F77C83DD5575307B15DBBDECA6F04D273
SHA384 9C75D86AE8730BC3E5E272D0B622C6C0F20870DBFAD69CA715338DB14C2067C6370316F2DF6CFEE8C816522B2B0D4E55
SHA512 ECB85B5435A2D35478857C269F9A61244CB3A0105AEB782201CE79B305D85B68A29B09A05C5070AF02951C0DE69A5618967DE7DDF674271F988B340ABE448CDC
SSDEEP 1536:yt3ItM+oMQwH9m+65tFI720+VpmDOzc4JNWxwB1MjVJmRc:yytMbEH9e/FO+VQDUcUNWs+jm6
IMP AAA5D23775A803F6978426A3C7A1F259
PESHA1 416E7DA0726A156FC5CA692883921D8FF773D45C
PE256 7D8BFC7023A31DB8460C438075325E87221FF25BF4A4EB32C2EA090353DE97C7

Signature

  • Status: Signature verified.
  • Serial: 33000001C422B2F79B793DACB20000000001C4
  • Thumbprint: AE9C1AE54763822EEC42474983D8B635116C8452
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: MdSched.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.17763.1 (WinBuild.160101.0800)
  • Product Version: 10.0.17763.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/69
  • VirusTotal Link: https://www.virustotal.com/gui/file/bc516f17afc7658c4f20726272d9ce9f77c83dd5575307b15dbbdeca6f04d273/detection/

File Similarity (ssdeep match)

File Score
C:\Windows\system32\MdRes.exe 80
C:\WINDOWS\system32\MdRes.exe 80
C:\Windows\system32\MdRes.exe 82
C:\windows\system32\MdRes.exe 77
C:\Windows\system32\MdRes.exe 80
C:\windows\system32\MdSched.exe 74
C:\Windows\system32\MdSched.exe 83
C:\Windows\system32\MdSched.exe 82
C:\WINDOWS\system32\MdSched.exe 80

MIT License. Copyright (c) 2020-2021 Strontic.