UevTemplateBaselineGenerator.exe
- File Path:
C:\WINDOWS\system32\UevTemplateBaselineGenerator.exe
- Description:
Screenshot
Hashes
Type | Hash |
---|---|
MD5 | 785B395FC7EB3F1876F02C263CBD82F7 |
SHA1 | 4DDAE3C94AFEB996FCB46992A38796205DBE8DF8 |
SHA256 | D3FCA9C011F6E349675F210C762CB0B30B86F95F2EEB54E435AF3DD843BA1775 |
SHA384 | 8069E87213BEEDF3E1490AE13924E929C76045F7994308378AD97665EF3C23B3858C81DFAD4D8A2719568D62E9B4385D |
SHA512 | A6F8076A7B842C5FC6909FD97D20F173AE525CED19E6074891DDF801C965F649DC77EF452B9ACE39A70E4D7847C8E46F724CB519D42AA81485EE2AA84FA7BD57 |
SSDEEP | 384:2X7qIjFc5wRMBQbBcYKPtIQX6GYp02MSK+aWZJW5Z:2LqIZc5taMBqTi |
IMP | F34D5F2D4577ED6D9CEEC516C1F5A744 |
PESHA1 | CA35A95D8AF295A69B078D85924E6F0C74B6B17F |
PE256 | 0DDD962CE45079F1A2444438E09B62F82C9B7D3360FED6304A3A2FDBADE17AEE |
Runtime Data
Child Processes:
conhost.exe
Window Title:
UevTemplateBaselineGenerator.exe - This application could not be started.
Open Handles:
Path | Type |
---|---|
(R-D) C:\Windows\Fonts\StaticCache.dat | File |
(R-D) C:\Windows\SysWOW64\en-US\user32.dll.mui | File |
(RW-) C:\Windows | File |
(RW-) C:\Windows\SysWOW64 | File |
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.22000.1_none_6ec7c6847ea94424 | File |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000001.db | Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db | Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro | Section |
\Sessions\2\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 | Section |
\Sessions\2\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 | Section |
\Sessions\2\Windows\Theme1077709572 | Section |
\Windows\Theme3461253685 | Section |
Loaded Modules:
Path |
---|
C:\WINDOWS\SYSTEM32\ntdll.dll |
C:\WINDOWS\system32\UevTemplateBaselineGenerator.exe |
C:\WINDOWS\System32\wow64.dll |
C:\WINDOWS\System32\wow64base.dll |
C:\WINDOWS\System32\wow64con.dll |
C:\WINDOWS\System32\wow64win.dll |
Signature
- Status: Signature verified.
- Serial:
33000002ED2C45E4C145CF48440000000002ED
- Thumbprint:
312860D2047EB81F8F58C29FF19ECDB4C634CF6A
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: UevTemplateBaselineGenerator.exe
- Product Name: Microsoft (R) Windows (R) Operating System
- Company Name: Microsoft Corporation
- File Version: 0.0.0.0
- Product Version: 0.0.0.0
- Language: Language Neutral
- Legal Copyright: Copyright (c) Microsoft Corporation. All rights reserved.
- Machine Type: 32-bit
File Scan
- VirusTotal Detections: 0/70
- VirusTotal Link: https://www.virustotal.com/gui/file/d3fca9c011f6e349675f210c762cb0b30b86f95f2eeb54e435af3dd843ba1775/detection
MIT License. Copyright (c) 2020-2021 Strontic.