ResetEngine.exe

  • File Path: C:\Windows\system32\ResetEngine.exe
  • Description: Push-Button Reset Engine

Hashes

Type Hash
MD5 09C06B0224F439DF8666CF7B411B7B1C
SHA1 DE53FC67D1E8995A4F068EEC644CA11844879ADF
SHA256 16F7DFCC1ECDCC2783A031510D413EDD98182A1BD117CB2DFEB2153768426CA5
SHA384 99FFB6EE8F265A4F904F7C84096A99D5918651671B98F14592EE9038945F4E4D534FB871BFE48E65FEFE7BD59CCC4620
SHA512 7BE18F5100E7314FB3815F4D014E65F8A980E8B58D2D3A1676F249B387FF8D599EB11AB1B44E8639A98DC5D98AB3C936BD6017BA9E38F538CF4973702AA94F87
SSDEEP 384:FlfHLUNi4m16fs41swWfeWEr6wDDBRJ54JeRlYA:/rC7LshEr6wD1PyK
IMP D1CCC9D0A0240603DC3279F82F80F8D3
PESHA1 A0FEF7CC9095C0357A17D5E91109289643329260
PE256 E983117C052D9BF74E26C1E9DFD0C509E18808A5832C9E2183464CDE25EA0D61

Runtime Data

Loaded Modules:

Path
C:\Windows\System32\ADVAPI32.dll
C:\Windows\System32\combase.dll
C:\Windows\System32\GDI32.dll
C:\Windows\System32\gdi32full.dll
C:\Windows\System32\IMM32.DLL
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\System32\msvcp_win.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\system32\ResetEngine.dll
C:\Windows\system32\ResetEngine.exe
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\sechost.dll
C:\Windows\System32\shcore.dll
C:\Windows\System32\SHELL32.dll
C:\Windows\System32\ucrtbase.dll
C:\Windows\System32\USER32.dll
C:\Windows\System32\win32u.dll

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: RESETENGINE.EXE
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.423 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.423
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/75
  • VirusTotal Link: https://www.virustotal.com/gui/file/16f7dfcc1ecdcc2783a031510d413edd98182a1bd117cb2dfeb2153768426ca5/detection

File Similarity (ssdeep match)

File Score
C:\Windows\system32\6bea57fb-8dfb-4177-9ae8-42e8b3529933_RuntimeDeviceInstall.dll 40
C:\Windows\system32\DeviceCensus.exe 27
C:\Windows\system32\LocationFrameworkPS.dll 29
C:\Windows\system32\migwiz\migres.dll 36
C:\Windows\system32\ResetEngine.exe 66
C:\Windows\system32\ResetEngine.exe 57
C:\Windows\system32\ResetEngine.exe 54
C:\Windows\system32\ScriptRunner.exe 41
C:\Windows\system32\ScriptRunner.exe 43
C:\Windows\system32\WerEnc.dll 30
C:\Windows\SystemApps\MicrosoftWindows.UndockedDevKit_cw5n1h2txyewy\UndockedDevKit.exe 47
C:\Windows\SysWOW64\backgroundTaskHost.exe 38
C:\Windows\SysWOW64\dllhost.exe 33
C:\Windows\SysWOW64\WerEnc.dll 32

MIT License. Copyright (c) 2020-2021 Strontic.