xcacls.exe
- File Path:
C:\Program Files (x86)\Spybot - Search & Destroy 2\xcacls.exe
Hashes
Type |
Hash |
MD5 |
98F2272A7D1BA8E3155FBEA167BCC613 |
SHA1 |
5315E172DD1F431A5C70EFA28E2960344190A3E9 |
SHA256 |
29DCE15201D8216AD847275ED8476699CD23ED48109F5362DA321094D1327FEF |
SHA384 |
2FBFA3C82B1ED4FB98CB7EE391A76CA3140F3648A6EDE1D24871EC7ADF74E9A2A4CBE55C1748792460E3AC349A7E3FC1 |
SHA512 |
48CCA17665832A8DF00997EB9C689204B052FFB9D92DB8C6D418223F4FC830833E01B99E1EF08A2F245B6D327D64F742754A1CB5A974AC55D05B7CFE051C17E4 |
SSDEEP |
1536:oUqpQA50nmB+w+HJVAHnY3gK/vawb30IIyhPJV4dZTZ6cegSfVWTxvoEequ:ojpQA50mBWJVMY3gK/vp0JyhRWZ6cezR |
IMP |
61B43C6BBA7C7E8BEA036E1228EF2969 |
PESHA1 |
4926F0F6B4A838B9BEB20C0081DA0C6F49B8F7DC |
PE256 |
8C2DF7A7545C729F3445E6B1F5E0181195962127F0AFF1A93616B2DF67FB568A |
Runtime Data
Usage (stderr):
The system cannot find the file specified.
Child Processes:
conhost.exe
Open Handles:
Path |
Type |
(RW-) C:\Windows |
File |
(RW-) C:\xCyclopedia |
File |
\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 |
Section |
\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 |
Section |
Loaded Modules:
Path |
C:\Program Files (x86)\Spybot - Search & Destroy 2\xcacls.exe |
C:\Windows\SYSTEM32\ntdll.dll |
C:\Windows\System32\wow64.dll |
C:\Windows\System32\wow64cpu.dll |
C:\Windows\System32\wow64win.dll |
Signature
- Status: The file C:\Program Files (x86)\Spybot - Search & Destroy 2\xcacls.exe is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/go.microsoft.com/fwlink/?LinkID=135170
- Serial: ``
- Thumbprint: ``
- Issuer:
- Subject:
- Original Filename:
- Product Name:
- Company Name:
- File Version:
- Product Version:
- Language:
- Legal Copyright:
- Machine Type: 32-bit
File Scan
- VirusTotal Detections: 0/68
- VirusTotal Link: https://www.virustotal.com/gui/file/29dce15201d8216ad847275ed8476699cd23ed48109f5362da321094d1327fef/detection/
MIT License. Copyright (c) 2020-2021 Strontic.