temp.000

Microsoft Windows NT Operating System

Eastman Kodak Company

Publisher:
Microsoft Corporation  (signed by Eastman Kodak Company)

Product:
Microsoft® Windows NT(TM) Operating System

Description:
Process Status Helper

Version:
4.00

MD5:
66212fe7d220c39bddb5f1c6779549b2

SHA-1:
fb89940bc8ee43c32d96d32374896c3b53da06db

SHA-256:
6959eda6e757e002baae78943046966059064c49dadbc366a553ca100ee14f29

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/27/2024 7:24:46 AM UTC  (today)

File size:
20 KB (20,512 bytes)

Product version:
4.00

Copyright:
Copyright © Microsoft Corp. 1981-1995

Original file name:
PSAPI

Language:
English (United States)

Common path:
C:\windows\syswow64\temp.000

Digital Signature
Authority:
Thawte Consulting (Pty) Ltd.

Valid from:
1/28/2010 7:00:00 PM

Valid to:
1/29/2012 6:59:59 PM

Subject:
CN=Eastman Kodak Company, OU=Graphics Communications Group, O=Eastman Kodak Company, L=Rochester, S=New York, C=US

Issuer:
CN=Thawte Code Signing CA, O=Thawte Consulting (Pty) Ltd., C=ZA

Serial number:
29AFFA5F7F19AA88CC534701EEA5FA6A

File PE Metadata
Compilation timestamp:
1/22/1996 10:37:08 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
2.60

CTPH (ssdeep):
384:AmrIEBQCn+l3nKzvGTpQ4WMSInlglWZCSWX1ggYJLlo9J:AtqvcQuPlgBL1gFLg

Entry address:
0x2791

Entry point:
8B, 44, 24, 08, 85, C0, 74, 07, 83, F8, 01, 74, 1B, EB, 3F, 64, A1, 18, 00, 00, 00, 8B, 40, 30, 8B, 48, 10, F6, 41, 08, 02, 74, 2D, E8, C5, F7, FF, FF, EB, 26, FF, 74, 24, 04, FF, 15, 48, 30, 5B, 74, 64, A1, 18, 00, 00, 00, 8B, 40, 30, 8B, 48, 10, F6, 41, 08, 02, 74, 0A, E8, 0A, 00, 00, 00, E8, E6, F1, FF, FF, B0, 01, C2, 0C, 00, 53, 56, 57, 33, DB, 55, 68, 08, 34, 5B, 74, 53, 6A, 02, FF, 15, 3C, 30, 5B, 74, 8B, F8, 85, FF, 0F, 84, 0E, 01, 00, 00, 53, 53, 53, 6A, 02, 57, FF, 15, 34, 30, 5B, 74, 8B, F0, 85...
 
[+]

Code size:
8 KB (8,192 bytes)

Scan temp.000 - Powered by Reason Core Security