NgcIso.exe

  • File Path: C:\Windows\system32\NgcIso.exe
  • Description: Windows Hello Security Process

Hashes

Type Hash
MD5 353EAB0594FDC93348280EDCDA8E0495
SHA1 2682A00E2C1E238A7B5E20E2D77F9C20445557BC
SHA256 BEBC95D47863245293261DDD67D273665CD485AEE4DF8562FE35E421925EBC4E
SHA384 E8D4D9463F06F927EDAD8514F7D37B580AB577C811B9AD53EA6E2F6104A684FCBCEA4C9C94D77F2ACB7C369529114187
SHA512 4FD0993F97DE10DD4CEAF50D975CFA87D74742D4B5A1081ABB8B3ABC5DC3ABBA05A46AD6441E2658FF5F994C165049D01A41FEB4BF8910A66928BC948F276AC9
SSDEEP 6144:UwW5mHtL2ut479u4ADYDK2AwiA/+wGWclDQ8L3vmf+IYf:hW5OC79PZAwEbQgvd7f
IMP 52E843A0E7736840CDCE9B4887B92406
PESHA1 272C20403A37798BA62156AB6E2802761BE82209
PE256 84BB7A48FD6EFA1D8C4485962D0AA79CDD5DDB2869ABA4F5326B837C41C1062F

Runtime Data

Loaded Modules:

Path
C:\Windows\system32\IumSdk.dll
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\System32\msvcp_win.dll
C:\Windows\system32\NgcIso.exe
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\ucrtbase.dll

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: NgcIso.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.423 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.423
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/75
  • VirusTotal Link: https://www.virustotal.com/gui/file/bebc95d47863245293261ddd67d273665cd485aee4df8562fe35e421925ebc4e/detection

MIT License. Copyright (c) 2020-2021 Strontic.