lpremove.exe

  • File Path: C:\Windows\system32\lpremove.exe
  • Description: MUI Language pack cleanup

Hashes

Type Hash
MD5 C1C6A67FA093B4218E20D7339039F09C
SHA1 E61DB7A6870D895FDB5402B0F80BB9BEEFC6CEE8
SHA256 148B7B678FE8E74F8D92412B14EFF11496D7B1AB7B8A548B327594F806DF77AF
SHA384 9D38684523CCB4E0BC00F4D45350B3E34CA43B106B8E5D635D308880AFC56012208B0C84F8ABADE7574F5551CC457947
SHA512 CBF7E71C910D0C497AA06F9A6EB805FD5BC35CC958112742AE0C012439381B8CA64FABD8D25B6280E210111D06A195B64C4B18A81C5378FF5EA801E1615481A7
SSDEEP 768:q67S3bre0GmpYMzKxFPhdMc4hID8bcoICZDMYDfUbcTv43bLTCXDp6rm08:q67L0Gm2bBQECVZDfUb1bfCXDp6rm08
IMP BC8B53A40E2042348C46E384FDE1F769
PESHA1 0E3D00DF24515ACF8815C775D7FB79C4F743EFF6
PE256 DEFB2A32C8CA0D09CE82000124CA0C9B65B713E4CB621C800222F2A88B50A901

Runtime Data

Loaded Modules:

Path
C:\Windows\System32\ADVAPI32.dll
C:\Windows\system32\AppXDeploymentClient.dll
C:\Windows\system32\Bcp47Langs.dll
C:\Windows\System32\bcryptPrimitives.dll
C:\Windows\System32\combase.dll
C:\Windows\System32\kernel.appcore.dll
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\system32\lpremove.exe
C:\Windows\System32\msvcp_win.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\sechost.dll
C:\Windows\system32\StateRepository.Core.dll
C:\Windows\System32\ucrtbase.dll

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: lpremove.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.17763.1 (WinBuild.160101.0800)
  • Product Version: 10.0.17763.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/148b7b678fe8e74f8d92412b14eff11496d7b1ab7b8a548b327594f806df77af/detection/

MIT License. Copyright (c) 2020-2021 Strontic.