AppVDllSurrogate32.exe

  • File Path: C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe
  • Description: AppVDllSurrogate32

Hashes

Type Hash
MD5 BB87D970CD29CC07A84A92E637ADD9A2
SHA1 D42BFEB740B65BFB75A3BA04258A9BFDF1278813
SHA256 A17CCEE308499360020E71EB305A5616D7B3163B02B20A26144355DC74E7F6CE
SHA384 FE14A7F3B21E7C54C8E2A96190603ABDCCF0370B540476BCA1D6A8C6FDA6ACD62527C3CD70C8B3FBD838382AEB5CACBB
SHA512 BADBF182E7C99EA1348ED2B39D69EB92D425AF1455831041D641B4800EA7C5D381FAD5A75CD599850E42F87847760A74B49AA0677CF397EF7F3B7E3A0F848B8D
SSDEEP 3072:V8oXN2vAEhk3ujDfkmmt0fSoD7EXG8ZiGB8xFAn:V80N2vAE+Bmmt0fSoD7KG4iGm
IMP 907CF5B9C00C513E347B1BB4516C2816
PESHA1 C02BCBE60C938681846FAF4A4E57D7121B2B29B7
PE256 C26B56AFC7E953A27ADFB7FDE9AB19CD477385F4A60AD0A07D06C8A75CAA39D5

Runtime Data

Loaded Modules:

Path
C:\Program Files (x86)\Microsoft Office\root\Client\AppVDllSurrogate32.exe
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll

Signature

  • Status: Signature verified.
  • Serial: 33000001519E8D8F4071A30E41000000000151
  • Thumbprint: 62009AAABDAE749FD47D19150958329BF6FF4B34
  • Issuer: CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: AppVDllSurrogate32.exe
  • Product Name: Microsoft Application Virtualization (App-V)
  • Company Name: Microsoft Corporation
  • File Version: 5.1.154.0
  • Product Version: 5.1.154.0
  • Language: English (United States)
  • Legal Copyright: 2015 Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/a17ccee308499360020e71eb305a5616d7b3163b02b20a26144355dc74e7f6ce/detection/

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\Microsoft Office\root\Client\AppVLP.exe 36
C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe 35
C:\Windows\SysWOW64\mavinject.exe 50
C:\WINDOWS\SysWOW64\mavinject.exe 33
C:\Windows\SysWOW64\mavinject.exe 38
C:\Windows\SysWOW64\mavinject.exe 46
C:\WINDOWS\SysWOW64\mavinject.exe 46
C:\Windows\SysWOW64\mavinject.exe 35
C:\Windows\SysWOW64\mavinject.exe 49
C:\Windows\SysWOW64\mavinject.exe 35

MIT License. Copyright (c) 2020-2021 Strontic.