nmscrub.exe

  • File Path: C:\WINDOWS\system32\nmscrub.exe

Hashes

Type Hash
MD5 C03B59334DAC244B60282E221B4DA5EF
SHA1 087F65C3E1ABA696081CC123C83DF3B630B4A916
SHA256 F43CBCAD3414C270F2833729E1E0B5523FBC87F043503EDD2F90AF38DAA5F11A
SHA384 2542D6E247DAACC38649606BFE192DF5B83D3A101C4337ADBE082F0A9301E1AA248C3399394E127D1D99779E2069EB35
SHA512 CAD19ACBF3EE3A1E90BD245F1BE08EE65073EE1905CF977E02F397D5B78EE26BE2128412996A17B5B3669FC64644F42014A12267FD66B6699820257C4572DB9E
SSDEEP 3072:2D4QAn2EgZZSK/UKLrVT69LGsCofBYlolBcmaYoldhT9yfPGk1roEfrTup:w4QlEgvFcK1BilEEiEfrTU

Runtime Data

Usage (stdout):


usage: nmscrub.exe
	-a    all virtual switches
	-h    HNS virtual switches
	-v    VMMS virtual switches
	-w    WSL virtual switches
	-i    HvsIcs virtual switches
	-n    display hyper-v NICs
	-t    display adapters
	-x    display extension adapters only
	-V    verbose output


Child Processes:

conhost.exe

Signature

  • Status: Signature verified.
  • Serial: 330000023241FB59996DCC4DFF000000000232
  • Thumbprint: FF82BC38E1DA5E596DF374C53E3617F7EDA36B06
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename:
  • Product Name:
  • Company Name:
  • File Version:
  • Product Version:
  • Language:
  • Legal Copyright:

File Similarity (ssdeep match)

File Score
C:\Windows\system32\nmbind.exe 43
C:\WINDOWS\system32\nmbind.exe 40
C:\Windows\system32\nmscrub.exe 36

MIT License. Copyright (c) 2020-2021 Strontic.