ZoomIt64.exe

  • File Path: C:\SysinternalsSuite\ZoomIt64.exe
  • Description: Sysinternals Screen Magnifier

Hashes

Type Hash
MD5 5FF026E5FE0E820E50D53BDDE9B714EC
SHA1 0D092576406FEC3CDFCB3F1E015A58245C248F37
SHA256 EBA52B395FD78779F288C1C718438B70FB3CFDF2FD0C547BA26B57639A036B52
SHA384 E1E1557BF46584AFB5B474E5EC976E53744812DF01B0BF34C8CD16C96F189E1F5E3451FBCA7B56BD429557617C6B6F79
SHA512 CBD30EE988EBF26929943B8F0934FC02B35DA3AD159360C35CD65548E5A65752485643368CF743AA4F714D43706404D9802AE4519936F832E91A7A0CAFB6B0BA
SSDEEP 12288:V8/f7k4IpXmvIxUfE2MlLBRPMS0aXgjTN2rAJ+9FB:h2wGfE2MlLBRPMS8/N2rAJ+V
IMP 6637F0F75092BB155D9DC80B73F6600B
PESHA1 FBCB43159C4837F2F375788A575755A8A6952C7D
PE256 EFD4BB94F86480D4788094FE79E524C99A487ED3ADE05F9482C207A15BBD5DFB

Runtime Data

Open Handles:

Path Type
(R-D) C:\Windows\Fonts\StaticCache.dat File
(R-D) C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9\comctl32.dll.mui File
(RW-) C:\Windows\WinSxS\amd64_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.19041.1_en-us_cb612d02732b0fd9 File
(RW-) C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21 File
(RW-) C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.508_none_faefa4f37613d18e File
(RW-) C:\xCyclopedia File
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section
\Sessions\1\Windows\Theme2036293991 Section
\Windows\Theme1324212991 Section

Loaded Modules:

Path
C:\SysinternalsSuite\ZoomIt64.exe
C:\Users\user\AppData\Local\Temp\ADInsightDll64.dll
C:\Windows\System32\ADVAPI32.dll
C:\Windows\System32\combase.dll
C:\Windows\System32\COMDLG32.dll
C:\Windows\System32\GDI32.dll
C:\Windows\System32\gdi32full.dll
C:\Windows\System32\imagehlp.dll
C:\Windows\System32\IMM32.DLL
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\MSIMG32.dll
C:\Windows\System32\msvcp_win.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\ole32.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\sechost.dll
C:\Windows\SYSTEM32\Secur32.dll
C:\Windows\System32\shcore.dll
C:\Windows\System32\SHELL32.dll
C:\Windows\System32\SHLWAPI.dll
C:\Windows\SYSTEM32\SSPICLI.DLL
C:\Windows\System32\ucrtbase.dll
C:\Windows\System32\USER32.dll
C:\Windows\System32\win32u.dll
C:\Windows\SYSTEM32\WINMM.dll
C:\Windows\WinSxS\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_ca04af081b815d21\COMCTL32.dll
C:\Windows\WinSxS\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.19041.508_none_faefa4f37613d18e\gdiplus.dll

Signature

  • Status: Signature verified.
  • Serial: 3300000187721772155940C709000000000187
  • Thumbprint: 2485A7AFA98E178CB8F30C9838346B514AEA4769
  • Issuer: CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: ZoomIt.exe
  • Product Name: Sysinternals ZoomIt
  • Company Name: Sysinternals - www.sysinternals.com
  • File Version: 4.52
  • Product Version: 4.52
  • Language: English (United States)
  • Legal Copyright: Copyright 2006-2019 Mark Russinovich
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/eba52b395fd78779f288c1c718438b70fb3cfdf2fd0c547ba26b57639a036b52/detection/

File Similarity (ssdeep match)

File Score
C:\SysinternalsSuite\ZoomIt.exe 77

Possible Misuse

The following table contains possible examples of ZoomIt64.exe being misused. While ZoomIt64.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_false_sysinternalsuite.yml - '\ZoomIt64.exe' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.