setupugc.exe

  • File Path: C:\Windows\SysWOW64\setupugc.exe
  • Description: Setup Unattend Generic Command Processor

Hashes

Type Hash
MD5 342CBB77B3F4B3F073DF2F042D20E121
SHA1 CF8D9A58B86E6A8ADCA5EE0B5D8E19F50B22DE93
SHA256 DE6FD33BA98DC97BDF55C29459A0AFD892DB9BA350BD3D0BAD4B8365E7E2BDBE
SHA384 239AFD60F268FFD0FFB3EF3B4413D5D800FA6F0180EA59C322EF5614DECF8B2F749A9B799982B2DD5201009BAF8EE6A0
SHA512 20B3B73F6A00A800860895E172E5A7D9A6FEA50897C00500171DFF4373E1EE581B0A7623E19D1191274E388B7C124CC6CD06535769311E01E34C93578FD8D157
SSDEEP 1536:AvDbihsvlQhLULLuvJGloM8eyTc4LD5y6lCf9DmQF0yRAyGM:AvBv++LLgGgeo53C9m20GAy
IMP D378AD4D96842E8513913645DEB96870
PESHA1 65903DA2101CB2AF9DA0E8C7CC9B11B4A2CBF786
PE256 4597BF2AC5E62DC36D6A75691CED0F766D1628B228DFF2382A51823CB4276C3A

Runtime Data

Child Processes:

explorer.exe

Loaded Modules:

Path
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll
C:\Windows\SysWOW64\setupugc.exe

Signature

  • Status: Signature verified.
  • Serial: 33000002EC6579AD1E670890130000000002EC
  • Thumbprint: F7C2F2C96A328C13CDA8CDB57B715BDEA2CBD1D9
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: SETUPUGC.EXE
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.746 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.746
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/74
  • VirusTotal Link: https://www.virustotal.com/gui/file/de6fd33ba98dc97bdf55c29459a0afd892db9ba350bd3d0bad4b8365e7e2bdbe/detection

MIT License. Copyright (c) 2020-2021 Strontic.