lpremove.exe

  • File Path: C:\Windows\system32\lpremove.exe
  • Description: MUI Language pack cleanup

Hashes

Type Hash
MD5 272B5EA7309039A904D254EDCC9796AB
SHA1 5296CB00CBF63FC0443D9BFDC1FE203D596CC497
SHA256 6220BA55D96DDAFB6B573B2405DB412F7420C77D09B5C1A1637D558EA5480057
SHA384 00272A16AAF69D93A271747B2653BABE82988E5EA806002EF61A6952FC73205D66F23B70EF656E629086B2943B408ADA
SHA512 018ED63A1FE4D233849D700F967243AE44A33172FE63CE1BC30A3028656DEFAAD41CAFDBDD6A1B6C7741B875DC9490CDFFAD6BDC2BB4570671A52364994F449E
SSDEEP 1536:K83joPP2VSiGrslo0QcOxizNpe02ZKljwa99xvbuMQnf5wTz5z3:7ujTrs2RFr02ZKdj6nfqz5T
IMP 2CE3B69EDF64B3D3627C181D0422215F
PESHA1 2EF4CF6429342007A5375D2A17F8751F82722A74
PE256 187477CF485FFB64AD8B6D3AEC3793976E167D1CD7A108706D3B60E5430354BD

Runtime Data

Loaded Modules:

Path
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\system32\lpremove.exe
C:\Windows\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: lpremove.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/76
  • VirusTotal Link: https://www.virustotal.com/gui/file/6220ba55d96ddafb6b573b2405db412f7420c77d09b5c1a1637d558ea5480057/detection

MIT License. Copyright (c) 2020-2021 Strontic.