accevent.exe
- File Path:
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x86\accevent.exe
- Description: Accessible Event Watcher (32-bit UNICODE Release)
Screenshot
Hashes
Type |
Hash |
MD5 |
F84263097B3C4DE7D584C1E6E2B778D8 |
SHA1 |
04895DFD3F5A385E2B51D64E7082165BC6F4E475 |
SHA256 |
1369E8F96E54732F45FFAC11C713892F2CDF7AB688BED4B70209DC964928314B |
SHA384 |
37BDC1BCEEB3BBBF9D2800F392DB2FE6B52CDB5A101D0C4F5E29CAC06DA479558DF757323624DB63F51E2F9044FCC082 |
SHA512 |
FAD76E4C298751CE36F6A6ADBD1C1629E8467B7849B47C2F2ECFB3629CD3E58E006525A0B8BD505D81C4A860A0DEA6675DCC820FF8FFBA782DF6479EB16F4A25 |
SSDEEP |
3072:zXhiTM8mP4P6QO3kMKYMKByf1aC6Z4GcQ7DpUfmKwCAq1lOKjU9N7r1tjky/XTg:jhiTM8mP4P6QO3kMKYMKBxhVcQ7+fxwY |
IMP |
ED1F8E0A43D91499C5EB87827CA878FF |
PESHA1 |
57135771CF26209386528186E1420EB702E076FE |
PE256 |
7840721B4771817407ADF467DC02CC7E36206F26413ADE4F64F1D0BB95DA5CBC |
Runtime Data
Window Title:
AccEvent - UIAutomation Events [Stopped]
Open Handles:
Path |
Type |
(R-D) C:\Windows\Fonts\StaticCache.dat |
File |
(RW-) C:\Users\user |
File |
(RW-) C:\Windows |
File |
(RW-) C:\Windows\SysWOW64 |
File |
(RW-) C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.488_none_11b1e5df2ffd8627 |
File |
\BaseNamedObjects__ComCatalogCache__ |
Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000002.db |
Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000002.db |
Section |
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2 |
Section |
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 |
Section |
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 |
Section |
\Sessions\1\Windows\Theme1383959086 |
Section |
\Windows\Theme2042523233 |
Section |
Loaded Modules:
Path |
C:\Program Files (x86)\Windows Kits\10\bin\10.0.19041.0\x86\accevent.exe |
C:\Windows\SYSTEM32\ntdll.dll |
C:\Windows\System32\wow64.dll |
C:\Windows\System32\wow64cpu.dll |
C:\Windows\System32\wow64win.dll |
Signature
- Status: Signature verified.
- Serial:
33000002CF6D2CC57CAA65A6D80000000002CF
- Thumbprint:
1A221B3B4FEF088B17BA6704FD088DF192D9E0EF
- Issuer: CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Original Filename: ACCEVENT.EXE
- Product Name: Microsoft Active Accessibility
- Company Name: Microsoft Corporation
- File Version: 7.2.0.0
- Product Version: 7.2.0.0
- Language: English (United States)
- Legal Copyright: 2012 Microsoft Corporation. All rights reserved.
- Machine Type: 32-bit
File Scan
- VirusTotal Detections: Unknown
File Similarity (ssdeep match)
MIT License. Copyright (c) 2020-2021 Strontic.