osloadw8.efi

OS Loader

SLI

Publisher:
Microsoft Corporation  (signed by SLI)

Product:
Microsoft® Windows® Operating System

Description:
OS Loader

Version:
6.3.9600.16384 (winblue_rtm.130821-1623)

MD5:
47f15ed2bbc9eade3ee4bfdc2416c9c5

SHA-1:
a47ead5e26bc1d65297d3959be02dd1b8dbd7277

SHA-256:
79d1ad41cf6414713c19c7d13d4077fba87107c3a0350243f92ba1498fccd1f4

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/20/2024 5:04:06 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W64.HfsAutoB
1.3.0.4959

File size:
1.6 MB (1,651,352 bytes)

Product version:
6.3.9600.16384

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
osloader.exe

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\wloaders\x64\osloadw8.efi

Digital Signature
Signed by:

Authority:
SLI

Valid from:
7/31/2011 7:52:10 AM

Valid to:
12/31/2039 11:59:59 PM

Subject:
CN=SLI

Issuer:
CN=SLI

Serial number:
B6D73A057CC856B648BA07BC372E9934

File PE Metadata
Compilation timestamp:
8/22/2013 12:41:44 PM

OS bitness:
Win64

Subsystem:

Linker version:
11.0

CTPH (ssdeep):
24576:U74Tl0o1qohDMg3L/OaD3Z6OORCYScvou4WqSd5xWMOTh1Go3Wre4mTBQTcB9MjL:U00UhgWTOaDsZHScvb4W/5x5OJ3WlT/H

Entry address:
0x61C0

Entry point:
48, 89, 5C, 24, 18, 55, 56, 57, 48, 8B, EC, 48, 81, EC, 80, 00, 00, 00, 8B, 79, 34, 48, 83, 65, C8, 00, 83, 65, E0, 00, 83, 65, F0, 00, 48, 83, 65, B8, 00, 41, B8, 00, 04, 00, 00, 44, 89, 45, D8, 48, 03, F9, C7, 45, D0, 14, 00, 00, 00, C7, 45, D4, 01, 00, 00, 00, 48, 8B, 45, D0, C7, 45, DC, 00, 00, 20, 00, 48, 89, 45, A0, 48, 8B, 45, D8, 48, 8D, 55, A0, 48, 89, 45, A8, 48, 8B, 45, E0, C7, 07, 01, 00, 00, 00, 48, 89, 45, B0, 48, 8B, 45, F0, C7, 45, A4, 01, 00, 00, 00, 48, 89, 45, C0, 48, 8D, 05, 27, 5B, 15...
 
[+]

Entropy:
6.4445

Code size:
1.3 MB (1,401,344 bytes)

Scan osloadw8.efi - Powered by Reason Core Security