AddInProcess.exe

  • File Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe
  • Description: AddInProcess.exe
  • Comments: Flavor=Retail

Hashes

Type Hash
MD5 929EA1AF28AFEA2A3311FD4297425C94
SHA1 2CA2E292B28CCA675DDF11EB1604208A724B59A0
SHA256 F0C5491DC3851DA576F0755319669C98809D82276B3E680350CD8E3F404F78F0
SHA384 6C16B85272AE123DC72A92AAF33DDC92FCADE3A62C9BAAAFA18169244C611B3C3FD744BF500E99DCF4C3FD0D43678454
SHA512 3DE842F1E5B4903F532709FF0A2BC5C2203B92960BF9B8CF963ED25B1D9B93B246C7D52259BCED44A7EA6B2757768F863913EE2BCE3C6E99CCE7082F07915FE0
SSDEEP 384:HvfIQRb67dOwRIeKJ9Yl6dnPU3SERztmbqCJstdMardz/JikPZ+6sPZZcWemn5fy:H3IX7dQ6Iq8eM/lG9TfqWh8fwL
IMP F34D5F2D4577ED6D9CEEC516C1F5A744
PESHA1 D14D37097D399D09637CC352B7D038E1D28F807D
PE256 5398E568D353CEEE75CB27CE9B020564466C613AB703D4F6FF58CF1F8A3808E9

Runtime Data

Loaded Modules:

Path
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe
C:\Windows\System32\KERNEL32.dll
C:\Windows\System32\KERNELBASE.dll
C:\Windows\SYSTEM32\MSCOREE.DLL
C:\Windows\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 330000023241FB59996DCC4DFF000000000232
  • Thumbprint: FF82BC38E1DA5E596DF374C53E3617F7EDA36B06
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: AddInProcess.exe
  • Product Name: Microsoft .NET Framework
  • Company Name: Microsoft Corporation
  • File Version: 4.8.4084.0 built by: NET48REL1
  • Product Version: 4.8.4084.0
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/75
  • VirusTotal Link: https://www.virustotal.com/gui/file/f0c5491dc3851da576f0755319669c98809d82276b3e680350cd8e3f404f78f0/detection

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\StoreAdm.exe 63
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Web.ApplicationServices.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Web.DynamicData.Design.dll 63
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe 71
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInUtil.exe 69
C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regbrowsers.exe 65
C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe 63
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe 100
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess32.exe 71
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInUtil.exe 69
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_regbrowsers.exe 63
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe 63

MIT License. Copyright (c) 2020-2021 Strontic.