dfsvc.exe

  • File Path: C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe
  • Description: ClickOnce
  • Comments: Flavor=Retail

Hashes

Type Hash
MD5 B1C06C3F89538F7B4F892D0A8F5E7EB9
SHA1 D855561DEA1B2DDA50D103EB9841BC08404E45C9
SHA256 584986978CEDE231BD748955F8A3777060FCCB4B942939476891DB25A37B3F3C
SHA384 4F9381ACB4A2B63D8C461DEFCB4DB58FCCECFAC061EF4BDE6A137389C8369B18C65999A4CC4E7D272D62D87ED214D15F
SHA512 F5AAE9F071867AE0C35198C05435AD54F791C98E0745E1F2B157D8FFD9D4BA57053E73E4371A419C92E9E4D64A283DEEBFAA096044FD09032F5CEA2064C50F48
SSDEEP 384:cNvDPZ2EWjX16WZFQSc+pBj0HRN7TGvcyHRN7rh4lrdQ:c1z4X1tZWeB
IMP F34D5F2D4577ED6D9CEEC516C1F5A744
PESHA1 EE287E19C5D2373DEE3009B56D075A43BE394D68
PE256 EFFBD85A21C41D65FAD86F0349D0DE986CF9C9D8DE8836A3621EF54DBB8FE3FC

Runtime Data

Open Handles:

Path Type
(R-D) C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll File
(RW-) C:\Windows\System32 File
...\Cor_SxSPublic_IPCBlock Section
\BaseNamedObjects__ComCatalogCache__ Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000001.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*{DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db Section
\BaseNamedObjects\C:*ProgramData*Microsoft*Windows*Caches*cversions.2.ro Section
\BaseNamedObjects\Cor_Private_IPCBlock_v4_8964 Section
\Sessions\2\BaseNamedObjects\NLS_CodePage_1252_3_2_0_0 Section
\Sessions\2\BaseNamedObjects\NLS_CodePage_437_3_2_0_0 Section

Loaded Modules:

Path
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscoreei.dll
C:\WINDOWS\System32\ADVAPI32.dll
C:\WINDOWS\System32\KERNEL32.dll
C:\WINDOWS\System32\KERNELBASE.dll
C:\WINDOWS\SYSTEM32\MSCOREE.DLL
C:\WINDOWS\System32\msvcrt.dll
C:\WINDOWS\SYSTEM32\ntdll.dll
C:\WINDOWS\System32\RPCRT4.dll
C:\WINDOWS\System32\sechost.dll

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: dfsvc.exe
  • Product Name: Microsoft .NET Framework
  • Company Name: Microsoft Corporation
  • File Version: 4.8.4161.0 built by: NET48REL1
  • Product Version: 4.8.4161.0
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/584986978cede231bd748955f8a3777060fccb4b942939476891db25a37b3f3c/detection

File Similarity (ssdeep match)

File Score
C:\PolicyAnalyzer_40\GPO2PolicyRules.exe 27
C:\Program Files (x86)\Microsoft Office\root\Office16\ADDINS\Microsoft Power Query for Excel Integrated\bin\Microsoft.Mashup.Container.exe 32
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\1033\flogvwrc.dll 40
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\1033\gacutlrc.dll 30
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\1033\IlDasmrc.dll 35
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\1033\pevrfyrc.dll 40
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\1033\snrc.dll 35
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\1033\TrackerUI.dll 36
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\x64\1033\flogvwrc.dll 40
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\x64\1033\gacutlrc.dll 27
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\x64\1033\IlDasmrc.dll 35
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\x64\1033\pevrfyrc.dll 41
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\x64\1033\snrc.dll 33
C:\Program Files (x86)\Microsoft SDKs\Windows\v10.0A\bin\NETFX 4.8 Tools\x64\1033\TrackerUI.dll 38
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Accessibility.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\Microsoft.Win32.Primitives.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.AppContext.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Collections.Concurrent.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Collections.dll 38
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Collections.NonGeneric.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Collections.Specialized.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ComponentModel.Annotations.dll 36
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ComponentModel.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ComponentModel.EventBasedAsync.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ComponentModel.Primitives.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ComponentModel.TypeConverter.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Console.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Data.Common.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Diagnostics.Contracts.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Diagnostics.Debug.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Diagnostics.FileVersionInfo.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Diagnostics.Process.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Diagnostics.StackTrace.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Diagnostics.TextWriterTraceListener.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Diagnostics.Tools.dll 46
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Diagnostics.TraceSource.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Drawing.Primitives.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Dynamic.Runtime.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Globalization.Calendars.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Globalization.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Globalization.Extensions.dll 52
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.IO.Compression.ZipFile.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.IO.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.IO.FileSystem.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.IO.FileSystem.DriveInfo.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.IO.FileSystem.Primitives.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.IO.FileSystem.Watcher.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.IO.IsolatedStorage.dll 50
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.IO.MemoryMappedFiles.dll 46
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.IO.Pipes.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.IO.UnmanagedMemoryStream.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Linq.dll 50
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Linq.Expressions.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Linq.Parallel.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Linq.Queryable.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Net.Http.Rtc.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Net.NameResolution.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Net.NetworkInformation.dll 46
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Net.Ping.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Net.Primitives.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Net.Requests.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Net.Security.dll 49
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Net.Sockets.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Net.WebHeaderCollection.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Net.WebSockets.Client.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Net.WebSockets.dll 38
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ObjectModel.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Reflection.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Reflection.Emit.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Reflection.Emit.ILGeneration.dll 38
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Reflection.Emit.Lightweight.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Reflection.Extensions.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Reflection.Primitives.dll 47
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Resources.Reader.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Resources.ResourceManager.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Resources.Writer.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.CompilerServices.VisualC.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.dll 38
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.Extensions.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.Handles.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.InteropServices.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.InteropServices.RuntimeInformation.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.InteropServices.WindowsRuntime.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.Numerics.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.Serialization.Formatters.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.Serialization.Json.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.Serialization.Primitives.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Runtime.Serialization.Xml.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Security.Claims.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Security.Cryptography.Algorithms.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Security.Cryptography.Csp.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Security.Cryptography.Encoding.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Security.Cryptography.Primitives.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Security.Cryptography.X509Certificates.dll 46
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Security.Principal.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Security.SecureString.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ServiceModel.Duplex.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ServiceModel.Http.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ServiceModel.NetTcp.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ServiceModel.Primitives.dll 38
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ServiceModel.Security.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Text.Encoding.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Text.Encoding.Extensions.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Text.RegularExpressions.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Threading.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Threading.Overlapped.dll 46
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Threading.Tasks.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Threading.Tasks.Parallel.dll 46
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Threading.Thread.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Threading.ThreadPool.dll 50
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Threading.Timer.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.ValueTuple.dll 46
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Xml.ReaderWriter.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Xml.XDocument.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Xml.XmlDocument.dll 41
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Xml.XmlSerializer.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Xml.XPath.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Facades\System.Xml.XPath.XDocument.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\ISymWrapper.dll 30
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\Microsoft.Activities.Build.dll 36
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\sysglobl.dll 35
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Activities.DurableInstancing.dll 29
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.AddIn.Contract.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.ComponentModel.Composition.Registration.dll 36
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Data.DataSetExtensions.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Data.Services.Design.dll 38
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Diagnostics.Tracing.dll 49
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.IO.Compression.dll 36
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.IO.Compression.FileSystem.dll 46
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Management.Instrumentation.dll 35
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Net.Http.WebRequest.dll 44
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Numerics.dll 33
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Reflection.Context.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Web.Abstractions.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Web.RegularExpressions.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Web.Routing.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Windows.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Windows.Input.Manipulations.dll 40
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Windows.Presentation.dll 43
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\System.Xml.Serialization.dll 50
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\UIAutomationClientsideProviders.dll 35
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\UIAutomationProvider.dll 36
C:\Program Files (x86)\Reference Assemblies\Microsoft\Framework.NETFramework\v4.8\XamlBuildTask.dll 29
C:\Windows\Microsoft.NET\Framework\v4.0.30319\dfsvc.exe 61
C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\Microsoft.Workflow.Compiler.exe 43
C:\Windows\Microsoft.NET\Framework\v4.0.30319\Microsoft.Workflow.Compiler.exe 38
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe 100
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe 61
C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Workflow.Compiler.exe 43
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Microsoft.Workflow.Compiler.exe 38
C:\Windows\system32\aspnet_counters.dll 38
C:\Windows\system32\msvcr100_clr0400.dll 44
C:\Windows\SysWOW64\aspnet_counters.dll 38
C:\Windows\SysWOW64\msvcr100_clr0400.dll 40

Possible Misuse

The following table contains possible examples of dfsvc.exe being misused. While dfsvc.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
LOLBAS Dfsvc.yml Name: Dfsvc.exe  
LOLBAS Dfsvc.yml Description: Executes click-once-application from Url (trampoline for Dfsvc.exe, DotNet ClickOnce host)  
LOLBAS Dfsvc.yml - Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\Dfsvc.exe  
LOLBAS Dfsvc.yml - Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Dfsvc.exe  
LOLBAS Dfsvc.yml - Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\Dfsvc.exe  
LOLBAS Dfsvc.yml - Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Dfsvc.exe  
LOLBAS Dfsvc.yml - Link: https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe  
LOLBAS Dfshim.yml Description: Executes click-once-application from Url (trampoline for Dfsvc.exe, DotNet ClickOnce host)  
LOLBAS Dfshim.yml - Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\Dfsvc.exe  
LOLBAS Dfshim.yml - Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Dfsvc.exe  
LOLBAS Dfshim.yml - Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\Dfsvc.exe  
LOLBAS Dfshim.yml - Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Dfsvc.exe  
LOLBAS Dfshim.yml - Link: https://stackoverflow.com/questions/13312273/clickonce-runtime-dfsvc-exe  

MIT License. Copyright (c) 2020-2021 Strontic.