Reason Labs

te.processhost.exe

Test Authoring and Execution Framework [v5.3-1509]

Microsoft Corporation

Publisher:
Microsoft Corporation  (signed and verified)

Product:
Microsoft® Windows® Operating System

Description:
Test Authoring and Execution Framework [v5.3-1509]

Version:
10.0.10582.1000 (th2_es_taef.151026-1520)

MD5:
baecfb4d510cac573700f5482461c2a8

SHA-1:
9505bf98a979f315dd9accc9e748f67c95f15c70

SHA-256:
d7199d6f3d2db9cca6b07f310588bfc57aca617ecd1429e4fe49f7c94c4a3208

Status:
Clean (as of last analysis)
Whitelisted  (by digital signature)

Analysis date:
11/16/2018 1:38:20 PM UTC  (today)

File size:
26.1 KB (26,736 bytes)

Product version:
10.0.10582.1000

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
TE.ProcessHost

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\microsoft visual studio 14.0\common7\ide\commonextensions\microsoft\testwindow\te.processhost.exe

Digital Signature
Authority:
Microsoft Corporation

Valid from:
6/4/2015 10:42:45 AM

Valid to:
9/4/2016 10:42:45 AM

Subject:
CN=Microsoft Corporation, OU=MOPR, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Issuer:
CN=Microsoft Code Signing PCA, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

Serial number:
330000010A2C79AED7797BA6AC00010000010A

File PE Metadata
Compilation timestamp:
10/26/2015 3:25:21 PM

OS version:
10.0

OS bitness:
Win32

Subsystem:
Windows Console

Linker version:
12.10

CTPH (ssdeep):
384:ILMXAtxuOBkRWSooWOqdoA0GftpBjSzw+ILKHRN7bXJla3OeUdCLTbFn1X8JD:ILdtgOBkDmKi0zwmbXaOMLTp1O

Entry address:
0x1600

Entry point:
E8, C3, 02, 00, 00, E9, 2E, FE, FF, FF, CC, CC, CC, CC, CC, CC, 3B, 0D, 04, 20, 40, 00, 75, 03, C2, 00, 00, E9, 35, 04, 00, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, 00, 81, 38, 63, 73, 6D, E0, 75, 2B, 83, 78, 10, 03, 75, 25, 8B, 40, 14, 3D, 20, 05, 93, 19, 74, 15, 3D, 21, 05, 93, 19, 74, 0E, 3D, 22, 05, 93, 19, 74, 07, 3D, 00, 40, 99, 01, 75, 06, FF, 15, 38, 30, 40, 00, 33, C0, 5D, C2, 04, 00, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC, CC...
 
[+]

Entropy:
6.7590

Code size:
3.5 KB (3,584 bytes)

There are numerous known versions of te.processhost.exe by Microsoft Corporation.

Clean
te.processhost.exe  6.3.9651.0 (winbluephone_rtm.140521-1530)  (8939faa8d31ce3a2a92cbfa15683b74bacfa75b1)

Clean
te.processhost.exe  10.0.14253.1001 (rs1_es_taef_vsupdate2.160512-1432)  (7e5ef8f38c3c80ddef671a83c9f479c62b1824fd)

Clean
te.processhost.exe  10.0.14253.1001 (rs1_es_taef_vsupdate2.160512-1416)  (d9cf243f1067cde5678bb06a679aad1a657bc361)

Clean
te.processhost.exe  10.0.14253.1001 (rs1_es_taef_vsupdate2.160307-1318)  (bb09aa94e6496efd5e582bc60f64350ceb8c74d0)

Clean
te.processhost.exe  10.0.14253.1001 (rs1_es_taef_vsupdate2.160307-1302)  (c2cacc79fa592ce33bf122676fc0d7fc3cda7977)

Clean
te.processhost.exe  10.0.10586.0 (th2_release.151029-1700)  (d02c3c1c4bad5a49215fec48a710758712ce6c11)

Clean
te.processhost.exe  10.0.10586.0 (th2_release.151029-1700)  (d9b4456270f8a8b2c33bbeb3dbdba372d79819af)

Clean
te.processhost.exe  10.0.10586.0 (th2_release.151029-1700)  (de2ae5bd58008f527be2b3ed1c32010042b0ce62)

Clean
te.processhost.exe  10.0.10586.0 (th2_release.151029-1700)  (d9e2f074abd06d63732c64af73db558acd077e01)

Clean
te.processhost.exe  10.0.10586.0 (th2_release.151029-1700)  (ee1c97755000279245923868a5281f2fa41c28dc)

Clean
te.processhost.exe  10.0.10586.0 (th2_release.151029-1700)  (fc8331ac48ede58d81a1143d637386fe3c901027)

Clean
te.processhost.exe  10.0.10586.0 (th2_release.151029-1700)  (bdc9991da6306198fc95b3af0291e0a4c684c73b)

Clean
te.processhost.exe  10.0.10582.1000 (th2_es_taef.151026-1541)  (dc3408effd9132cb0ed9047fa938381390585d38)

Clean
te.processhost.exe  10.0.10526.1000 (th2_es_taef.150814-1643)  (0f41f0bd675b27d27cf55ecaf3cc98f9510cad88)

Clean
te.processhost.exe  10.0.10526.1000 (th2_es_taef.150814-1623)  (0e2d44bcb6bafee9c6f270b07ec3f0b90d51de95)

Clean
ntdll.dll  (3a2bae6036ff2d23309a7b93ab562494c50df236)

Clean
rsaenh.dll  (a1c8e3e6ee44dcb68752d44b3b6f4ecce89c388d)

Clean
bcryptprimitives.dll  (f76bb1b4d0ad47f68f8381281f87839304c252ea)

Clean
sqmapi.dll  (2fcd13bd14c631279ce4c5fd96b448d4dded5b11)

Clean
wuapi.dll  (46eed9639adc4e9cc6e2f5db5edf992b031928d8)

Clean
wuauclt.exe  (883d5312d7f6bf03ab56761ff110784e4ba2edec)

Clean
wups2.dll  (9a68d7eed00c944a51c8c53caeb3c9e23db6106b)

Clean
fveapi.dll  (1700a976565404226ff0704e4e2d9d8410bc6721)

Clean
wuaueng.dll  (64a55a014a2de34f86f17cfa31c727e270fcd83f)

Clean
dssenh.dll  (e395683841b965d1f224413f2e3339091f51add8)

Clean
dxwebsetup.exe  (3c8243734cf43dd7bb2332ba05b58ccacfa4377c)

Clean
portqryui.exe  (aa59ac1f61e87fd08ae371743b9aa12e16cc9d9a)

Clean
acpi.sys  (54fb26c69829d3f1d0774d4e608327ffefa34d76)

Clean
atapi.sys  (954d59eaeadc36cb19a224a5dddfa1edcfdc49ce)

Clean
clfs.sys  (df95d1fe3fcc8417da0ae9479612b7be398b36a4)

Clean
cng.sys  (c0f3a5bc240d2d26fa7e23bf27dc5a4876ff5296)

Download Reason Core Security - Powerful anti-malware software