osloadwv.efi

OS Loader

SLI

Publisher:
Microsoft Corporation  (signed by SLI)

Product:
Microsoft® Windows® Operating System

Description:
OS Loader

Version:
6.0.6002.18005 (lh_sp2rtm.090410-1830)

MD5:
21805bca27f2fee0c47d38ddcbe2ffdf

SHA-1:
f9494e97e5f9670f8672c3f1cf392a70f0eea636

SHA-256:
d89d8d9b88426faaf1456cfeedec12f8a5fe5bb0679e4fd71419639cdfd0346c

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
4/25/2024 7:12:54 AM UTC  (today)

Scan engine
Detection
Engine version

Bkav FE
W64.HfsAutoB
1.3.0.4959

File size:
1 MB (1,081,456 bytes)

Product version:
6.0.6002.18005

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
osloader.exe

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\wloaders\x64\osloadwv.efi

Digital Signature
Signed by:

Authority:
SLI

Valid from:
7/31/2011 7:52:10 AM

Valid to:
12/31/2039 11:59:59 PM

Subject:
CN=SLI

Issuer:
CN=SLI

Serial number:
B6D73A057CC856B648BA07BC372E9934

File PE Metadata
Compilation timestamp:
4/11/2009 5:53:53 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:

Linker version:
8.0

CTPH (ssdeep):
24576:GYGOPU75JBvhf+qL+6mp4qRq22T52sCnXGxoqOp:9GaqBvhfafpeYDXMap

Entry address:
0x1000

Entry point:
48, 8B, C4, 48, 89, 58, 10, 48, 89, 70, 18, 57, 48, 83, EC, 70, 8B, 79, 34, 83, 60, B8, 00, 48, 83, 60, C0, 00, 83, 60, C8, 00, 48, 03, F9, 48, 8B, F1, 48, 8D, 48, D0, 48, 8D, 50, A8, BB, 00, 04, 00, 00, 41, B8, 28, 00, 00, 00, C7, 07, 01, 00, 00, 00, C7, 40, A8, 14, 00, 00, 00, C7, 40, AC, 01, 00, 00, 00, 89, 58, B0, C7, 40, B4, 00, 00, 20, 00, E8, E4, F6, 04, 00, 89, 5C, 24, 68, 8B, 5C, 24, 48, F6, C3, 02, C7, 44, 24, 4C, 01, 00, 00, 00, C7, 44, 24, 58, 00, 00, 02, 00, 48, 8D, 54, 24, 48, 74, 62, 48, 8D...
 
[+]

Entropy:
7.4818

Code size:
377 KB (386,048 bytes)

Scan osloadwv.efi - Powered by Reason Core Security