provlaunch.exe

  • File Path: C:\Windows\system32\provlaunch.exe
  • Description: Provisioning package runtime command launching tool

Hashes

Type Hash
MD5 7BB8F781477C0870B70EB33262D28FCE
SHA1 27E3853E6F4E30B7563F4E2067179BD243B62E54
SHA256 337569C120A3F113A4DFD907427D939A44D60DA2E6D300C85C8A286048BFD851
SHA384 37C078A4F7C66D8B377F45C32F5AAF1A5DB1DCDA6B46061288F572D71A44084E89E0C9E308BCDE9957B495811C9207D9
SHA512 784E05F8E9061FAAF2564E78A3807B53E710CEE505A411A3C9EB4187E3F8ED1009579457D136572EC4A8063308A337705A44630E57A1E9C7CCE9A630BE480185
SSDEEP 1536:sNNugGdLPLu975SqHG1TQIolWLzmuuQKrXzbB3QzO7Os:sDMulsqIQblWF98jb1QS7Os
IMP 3E0DDAB92FCD1DD5AB2C7083DBECEB31
PESHA1 6FEF29B1A515D864D591F6982DFD029E5FFA4ED1
PE256 E12C39AC61EC2D8D4B34681DBE53578591C292224A3697A5201BF74E494CDCEA

Runtime Data

Loaded Modules:

Path
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\system32\provlaunch.exe

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: provlaunch
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/74
  • VirusTotal Link: https://www.virustotal.com/gui/file/337569c120a3f113a4dfd907427d939a44d60da2e6d300c85c8a286048bfd851/detection

MIT License. Copyright (c) 2020-2021 Strontic.