ddodiag.exe

  • File Path: C:\WINDOWS\SysWOW64\ddodiag.exe
  • Description: DDODiag is a tool that collects Device Display Object (DDO) information from the system and logs it

Hashes

Type Hash
MD5 CD55C8ECAAD24E86B41DEC2A551D8528
SHA1 D8834D206725792DB5EE590C8724B57D7DAA98AB
SHA256 D9FCFB3C176EA76D997C98A492E54A00DBA2D584FDB46280062EE7354828B3F7
SHA384 D9B612BFED0AB3349845A66D5B7A8F108376407C6D61E6AEF0EE9A115034BD58030D7C3A3D458E5FFF039E0FC6990575
SHA512 E0E53E28E3DFAD00BA162F493F129C7181D1DBF695B2A10F507F52C80A08F620EB77F2AF6325E1C5D86127FDC6E2F9E7A51E10519E48EEFD3DAE18D2F53CB12F
SSDEEP 768:bBAm6fhsXKZkrWcwMa4uZlqi+kShv48fj5C13n:bBAm6fhsXKZkrWcwMa4uZlqi8p4E83n
IMP B43CCBC6C55900E84EECEC9A08752C16
PESHA1 DDAF093E2B4442A510FA2AE26E83D4B55CA09D95
PE256 AF1D27CB1DC148BB7A0ACAD154F31C3269C6B2CCEE7C7B42B026BB139B285820

Runtime Data

Loaded Modules:

Path
C:\WINDOWS\SYSTEM32\ntdll.dll
C:\WINDOWS\System32\wow64.dll
C:\WINDOWS\System32\wow64base.dll
C:\WINDOWS\System32\wow64con.dll
C:\WINDOWS\System32\wow64cpu.dll
C:\WINDOWS\System32\wow64win.dll
C:\WINDOWS\SysWOW64\ddodiag.exe

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: DDODiag.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.22000.1 (WinBuild.160101.0800)
  • Product Version: 10.0.22000.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/d9fcfb3c176ea76d997c98a492e54a00dba2d584fdb46280062ee7354828b3f7/detection

File Similarity (ssdeep match)

File Score
C:\Windows\SysWOW64\ddodiag.exe 74
C:\windows\SysWOW64\ddodiag.exe 71
C:\WINDOWS\SysWOW64\ddodiag.exe 71
C:\Windows\SysWOW64\ddodiag.exe 71
C:\Windows\SysWOW64\ddodiag.exe 74

MIT License. Copyright (c) 2020-2021 Strontic.