doc.exe

Windows Problem Reporting

XetGo Software Ltd.

Publisher:
Microsoft Corporation  (signed by XetGo Software Ltd.)

Product:
Microsoft® Windows® Operating System

Description:
Windows Problem Reporting

Version:
6.1.7600.16385 (win7_rtm.090713-1255)

MD5:
87fd1ad0f915629c9a9459c61242ef3d

SHA-1:
2300d4e410d27de15e4afec5b0dc963e6bb4be3a

SHA-256:
e35e37d64978bf5560ed4b596e6794f05d02d570f10bd0bca7b7ae2c258e4bce

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 4:57:58 AM UTC  (today)

File size:
370.1 KB (378,996 bytes)

Product version:
6.1.7600.16385

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
WerFault.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\roaming\doc.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
12/19/2012 7:00:00 PM

Valid to:
12/20/2014 6:59:59 PM

Subject:
CN=XetGo Software Ltd., O=XetGo Software Ltd., STREET=1840 Knutsford Place, L=Victoria, S=BC, PostalCode=V8N 6E4, C=CA

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00EF51E3D40CEB9F88AEF48ADACCEF46E4

File PE Metadata
Compilation timestamp:
11/21/2014 11:31:28 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.0

CTPH (ssdeep):
6144:g8sOWvCVoxWCmzUiQbbHhDPx3IfTYjDQ8g5J/ZAv5lFd+V5WnbFwPYzDNf:g8svxWdzjQbzhV3pjcpJ/2xMYwPYPNf

Entry address:
0x111C

Entry point:
68, 04, 13, 10, 01, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 05, 98, 0C, EB, 76, 71, AC, 46, BF, 5A, 68, C5, 4B, 65, 9F, EB, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 2D, 43, 30, 30, 30, 2D, 49, 6E, 74, 65, 6C, 6C, 69, 73, 65, 6E, 73, 65, 00, 23, 32, 2E, 00, 00, 00, 00, FF, CC, 31, 00, 00, FE, 65, 63, F6, B6, 40, 5F, 44, 8F, 81, 94, FC, 6C, 30, CB, 0E, 28, F8, 77, 24, D6, 96, A3, 4E, 80, E4, 6C, 0D, CC, A7, 52, FD, 3A, 4F, AD, 33, 99, 66, CF, 11, B7, 0C, 00...
 
[+]

Entropy:
7.2963

Developed / compiled with:
Microsoft Visual Basic v5.0

Code size:
64 KB (65,536 bytes)

Scan doc.exe - Powered by Reason Core Security