AddInProcess32.exe

  • File Path: C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
  • Description: AddInProcess.exe
  • Comments: Flavor=Retail

Hashes

Type Hash
MD5 816A42D47AA933E55428DF42C2BA8505
SHA1 958C1048B05FF099E343E58C3C1C12C7C4B652C9
SHA256 4193D9EC5FD54C80CCB9BFCC990A7BB6862A78DD196D6DCF9345283D7C40FB24
SHA384 53703AFDA8DC35ACFC4AD419637B143C2CE7B822B039C1568FAA35CC523C5285FEAEDCC9F59F62965950BA323EB10CE0
SHA512 82731CB62CDCB5873DD4A87A4F5CD27B3134015134EA6D2A6C6C1CDCAB915AC262763A811DEE3CBC3689ABA0A2472B25940E7339F8FBA02F6E51D9FF206749AF
SSDEEP 384:bc3JOvwWj8Gpw0A67dOpR+XKJ9Yl6dnPU3SERztmbqCJstdMardz/JikPZ+9sPZo:b4JU8g17dg6Iq8xMYnuJWCDL3y
IMP F34D5F2D4577ED6D9CEEC516C1F5A744
PESHA1 9AF87BA0F9741BCDA448FD97F8FAD4DD57F2CD57
PE256 235B79A58482469649CE3AF3C7A0AAEFA47D957B9CD056FF5A01DBD07325E4A6

Runtime Data

Loaded Modules:

Path
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe
C:\WINDOWS\SYSTEM32\ntdll.dll
C:\WINDOWS\System32\wow64.dll
C:\WINDOWS\System32\wow64base.dll
C:\WINDOWS\System32\wow64con.dll
C:\WINDOWS\System32\wow64cpu.dll
C:\WINDOWS\System32\wow64win.dll

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: AddInProcess32.exe
  • Product Name: Microsoft .NET Framework
  • Company Name: Microsoft Corporation
  • File Version: 4.8.4161.0 built by: NET48REL1
  • Product Version: 4.8.4161.0
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/74
  • VirusTotal Link: https://www.virustotal.com/gui/file/4193d9ec5fd54c80ccb9bfcc990a7bb6862a78dd196d6dcf9345283d7c40fb24/detection

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\StoreAdm.exe 63
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Web.ApplicationServices.dll 46
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Web.DynamicData.Design.dll 65
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe 71
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\AddInProcess.exe 71
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInProcess32.exe 93
C:\Windows\Microsoft.NET\Framework\v4.0.30319\AddInUtil.exe 68
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\AddInUtil.exe 68
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_regbrowsers.exe 65
C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_regbrowsers.exe 66
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe 68
C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe 66
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe 71
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\AddInProcess.exe 71
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\AddInProcess32.exe 100
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInProcess32.exe 93
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\AddInUtil.exe 68
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\AddInUtil.exe 68
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\aspnet_regbrowsers.exe 63
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_regbrowsers.exe 63
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe 66
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe 65

MIT License. Copyright (c) 2020-2021 Strontic.