windeployetw.dll

Windeploy ETW Event Resources

Windows Central Build Account

Publisher:
Microsoft Corporation  (signed by Windows Central Build Account)

Product:
Microsoft® Windows® Operating System

Description:
Windeploy ETW Event Resources

Version:
10.0.10569.1001 (th2_sigma_grfx.151013-1800)

MD5:
146da55c1a5fe2c885ac68a0855bd1b5

SHA-1:
fbc6b32658090872ea9e2ee26a322f63630cab0d

SHA-256:
efebcae83513225ca9fbf29a985d9b31c354f0bec2bd23dc69ddc0fb19c5b3d2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
5/9/2024 9:21:03 AM UTC  (today)

File size:
12.6 KB (12,920 bytes)

Product version:
10.0.10569.1001

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
windeployetw.dll.mui

File type:
Dynamic link library (Win64 DLL)

Language:
English (United States)

Digital Signature
Authority:
MSIT Test CodeSign CA 2

Valid from:
4/8/2015 1:59:31 AM

Valid to:
4/7/2016 1:59:31 AM

Subject:
CN=Windows Central Build Account

Issuer:
CN=MSIT Test CodeSign CA 2, DC=redmond, DC=corp, DC=microsoft, DC=com

Serial number:
77005CBFF66633247B2FA2FD7C0003005CBFF6

File PE Metadata
Compilation timestamp:
10/14/2015 2:31:09 PM

OS version:
10.0

OS bitness:
Win64

Subsystem:
Windows Console

Linker version:
12.10

CTPH (ssdeep):
192:PQWKkWZGUoMN4miW7Aj/cDszpPuTlA9kcbfW/2EZjPOdbIvNZ8:4WKkWZDo760/flBbuJy

Entry point:
4D, 5A, 90, 00, 03, 00, 00, 00, 04, 00, 00, 00, FF, FF, 00, 00, B8, 00, 00, 00, 00, 00, 00, 00, 40, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, C0, 00, 00, 00, 0E, 1F, BA, 0E, 00, B4, 09, CD, 21, B8, 01, 4C, CD, 21, 54, 68, 69, 73, 20, 70, 72, 6F, 67, 72, 61, 6D, 20, 63, 61, 6E, 6E, 6F, 74, 20, 62, 65, 20, 72, 75, 6E, 20, 69, 6E, 20, 44, 4F, 53, 20, 6D, 6F, 64, 65, 2E, 0D, 0D, 0A, 24, 00, 00, 00, 00, 00, 00, 00...
 
[+]

Entropy:
6.2986

Scan windeployetw.dll - Powered by Reason Core Security