provlaunch.exe
- File Path:
C:\Windows\system32\provlaunch.exe
- Description: Provisioning package runtime command launching tool
Hashes
Type |
Hash |
MD5 |
7BB8F781477C0870B70EB33262D28FCE |
SHA1 |
27E3853E6F4E30B7563F4E2067179BD243B62E54 |
SHA256 |
337569C120A3F113A4DFD907427D939A44D60DA2E6D300C85C8A286048BFD851 |
SHA384 |
37C078A4F7C66D8B377F45C32F5AAF1A5DB1DCDA6B46061288F572D71A44084E89E0C9E308BCDE9957B495811C9207D9 |
SHA512 |
784E05F8E9061FAAF2564E78A3807B53E710CEE505A411A3C9EB4187E3F8ED1009579457D136572EC4A8063308A337705A44630E57A1E9C7CCE9A630BE480185 |
SSDEEP |
1536:sNNugGdLPLu975SqHG1TQIolWLzmuuQKrXzbB3QzO7Os:sDMulsqIQblWF98jb1QS7Os |
IMP |
3E0DDAB92FCD1DD5AB2C7083DBECEB31 |
PESHA1 |
6FEF29B1A515D864D591F6982DFD029E5FFA4ED1 |
PE256 |
E12C39AC61EC2D8D4B34681DBE53578591C292224A3697A5201BF74E494CDCEA |
Runtime Data
Loaded Modules:
Path |
C:\Windows\System32\KERNEL32.DLL |
C:\Windows\System32\KERNELBASE.dll |
C:\Windows\SYSTEM32\ntdll.dll |
C:\Windows\system32\provlaunch.exe |
Signature
- Status: Signature verified.
- Serial:
3300000266BD1580EFA75CD6D3000000000266
- Thumbprint:
A4341B9FD50FB9964283220A36A1EF6F6FAA7840
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Original Filename: provlaunch
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.19041.1 (WinBuild.160101.0800)
- Product Version: 10.0.19041.1
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 64-bit
File Scan
- VirusTotal Detections: 0/74
- VirusTotal Link: https://www.virustotal.com/gui/file/337569c120a3f113a4dfd907427d939a44d60da2e6d300c85c8a286048bfd851/detection
MIT License. Copyright (c) 2020-2021 Strontic.