adplusmanager.exe
- File Path:
C:\Program Files (x86)\Windows Kits\10\Debuggers\x86\adplusmanager.exe
- Description:
Hashes
Type | Hash |
---|---|
MD5 | 3A6F1EE12C9A6189B127DC7BC314C002 |
SHA1 | 8AD6352A2D93E7AF4833C3F225AF9559AA0DF376 |
SHA256 | 41B4ABB46D95A5D85F64D99E4D86B9785EEA0144F905B133795D227354871717 |
SHA384 | 3B5326862C927371B3B342098EC5A339CAD8171549491DE212AC425E35F2970B547F9DEA7D0A190316E6D8BE81530908 |
SHA512 | 9D6A9CD303AFF4796EFD188F5A7D83CDA321A0CE6E328E8AA259E0A6CB398B40D1F9944B040E820DA319D636288A9B7AC64AED5793C76730DEDB8289EB375264 |
SSDEEP | 768:tZsFKlZ8Kc41WjT4TNegAuDk+rGbG/+B+OzUaGNUXXpidOD:7luaWgpRDkPbr+68OXXYQ |
IMP | F34D5F2D4577ED6D9CEEC516C1F5A744 |
PESHA1 | 36E69E1645A97F8E5F8DBAF6E3484F15F2FAD66C |
PE256 | 053B3AEC10557775F59DE8C7BA3C72430C3F486754AA9C3AC262B903E5A8BDDF |
Runtime Data
Child Processes:
Fondue.exe
Loaded Modules:
Path |
---|
C:\Program Files (x86)\Windows Kits\10\Debuggers\x86\adplusmanager.exe |
C:\Windows\System32\ADVAPI32.dll |
C:\Windows\System32\KERNEL32.dll |
C:\Windows\System32\KERNELBASE.dll |
C:\Windows\SYSTEM32\MSCOREE.DLL |
C:\Windows\System32\msvcrt.dll |
C:\Windows\SYSTEM32\ntdll.dll |
C:\Windows\System32\RPCRT4.dll |
C:\Windows\System32\sechost.dll |
Signature
- Status: Signature verified.
- Serial:
33000002CF6D2CC57CAA65A6D80000000002CF
- Thumbprint:
1A221B3B4FEF088B17BA6704FD088DF192D9E0EF
- Issuer: CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
File Metadata
- Original Filename: AdplusManager.exe
- Product Name: Microsoft (R) Windows (R) Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.19041.1
- Product Version: 10.0.19041.1
- Language: Language Neutral
- Legal Copyright: Copyright (c) Microsoft Corporation. All rights reserved.
- Machine Type: 32-bit
File Scan
- VirusTotal Detections: Unknown
File Similarity (ssdeep match)
MIT License. Copyright (c) 2020-2021 Strontic.