newdev.exe

  • File Path: C:\Windows\SysWOW64\newdev.exe
  • Description: Device driver software installation

Hashes

Type Hash
MD5 775D479963E7ED5969665E44D8859438
SHA1 FEC95531CA2DA4FC455478F9131AEB2EDD65AC3F
SHA256 7282CDBEB71F9ACEEE4E8843054B1AEBDF47893439CDD2EDC61E6349B89FD423
SHA384 272B09C791F90CF57EE349345FC34EA2E41B90BFEEAD71E679160F3C8E9C7D007A80C428DE5887CD6C4F70CC71B1F776
SHA512 29007ED91A5456010231775CBAD88F3DEFFCAB4F01E4C5BB9A4FDCE342067132AD41989000559D35F708F663554BEC655C0470E5A19C2A16E8F2CB377DCA7C7B
SSDEEP 768:0iFs97OzKj2h29aJQAhtqIrn8+1hrpFIUUUUUUUUUUUUqRcxMF:NFsBOzvh29aJfFrGUUUUUUUUUUUU3+F
IMP B4DC1C33BAF719825A5B35608B2A72A8
PESHA1 B0F80B1ABBBDA23475C36AD5CCD1E4457738B3E6
PE256 4AB5B4FF8CC9A5A18A9878175BBDE708589AC373C6322310A6EF632DB21EBE6D

Runtime Data

Loaded Modules:

Path
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll
C:\Windows\SysWOW64\newdev.exe

Signature

  • Status: Signature verified.
  • Serial: 33000002EC6579AD1E670890130000000002EC
  • Thumbprint: F7C2F2C96A328C13CDA8CDB57B715BDEA2CBD1D9
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: NewDev.EXE
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 5.2.3668.0
  • Product Version: 5.2.3668.0
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/72
  • VirusTotal Link: https://www.virustotal.com/gui/file/7282cdbeb71f9aceee4e8843054b1aebdf47893439cdd2edc61e6349b89fd423/detection

File Similarity (ssdeep match)

File Score
C:\Windows\system32\ndadmin.exe 68
C:\Windows\system32\ndadmin.exe 72
C:\Windows\system32\ndadmin.exe 68
C:\WINDOWS\system32\ndadmin.exe 65
C:\WINDOWS\system32\ndadmin.exe 68
C:\Windows\system32\ndadmin.exe 66
C:\Windows\system32\ndadmin.exe 71
C:\Windows\system32\newdev.exe 46
C:\WINDOWS\system32\newdev.exe 55
C:\Windows\system32\newdev.exe 55
C:\Windows\system32\newdev.exe 58
C:\Windows\system32\newdev.exe 50
C:\WINDOWS\system32\newdev.exe 65
C:\Windows\system32\newdev.exe 52
C:\Windows\system32\pnpclean.dll 27
C:\Windows\SysWOW64\ndadmin.exe 69
C:\Windows\SysWOW64\ndadmin.exe 69
C:\Windows\SysWOW64\ndadmin.exe 69
C:\Windows\SysWOW64\ndadmin.exe 71
C:\Windows\SysWOW64\ndadmin.exe 74
C:\WINDOWS\SysWOW64\ndadmin.exe 68
C:\WINDOWS\SysWOW64\ndadmin.exe 65
C:\Windows\SysWOW64\newdev.exe 90
C:\Windows\SysWOW64\newdev.exe 77
C:\Windows\SysWOW64\newdev.exe 90
C:\WINDOWS\SysWOW64\newdev.exe 57
C:\WINDOWS\SysWOW64\newdev.exe 68
C:\Windows\SysWOW64\newdev.exe 74

MIT License. Copyright (c) 2020-2021 Strontic.