osloadwv.exe

OS Loader

SLI

Publisher:
Microsoft Corporation  (signed by SLI)

Product:
Microsoft® Windows® Operating System

Description:
OS Loader

Version:
6.0.6002.18005 (lh_sp2rtm.090410-1830)

MD5:
d95c2c75ebba627b970bd8b2fe3cea42

SHA-1:
340b0e2fe4991b0058713234433e87fd45642f76

SHA-256:
f062a1a1b520362e15eca66e1d78bd7709f520eab913c64eaa16e76bb1e409d2

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/19/2024 6:59:41 PM UTC  (today)

File size:
1 MB (1,068,144 bytes)

Product version:
6.0.6002.18005

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
osloader.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\wloaders\x64\osloadwv.exe

Digital Signature
Signed by:

Authority:
SLI

Valid from:
7/31/2011 7:52:10 AM

Valid to:
12/31/2039 11:59:59 PM

Subject:
CN=SLI

Issuer:
CN=SLI

Serial number:
B6D73A057CC856B648BA07BC372E9934

File PE Metadata
Compilation timestamp:
4/11/2009 5:53:59 AM

OS version:
4.0

OS bitness:
Win64

Subsystem:

Linker version:
8.0

CTPH (ssdeep):
24576:E9T9HkUISlvd5A84D+63kp4qRq22T52sCnXGxoqO0:aTBkMxd5zL9peYDXMa0

Entry address:
0x1000

Entry point:
48, 8B, C4, 48, 89, 58, 10, 48, 89, 70, 18, 57, 48, 83, EC, 70, 8B, 79, 34, 83, 60, B8, 00, 48, 83, 60, C0, 00, 83, 60, C8, 00, 48, 03, F9, 48, 8B, F1, 48, 8D, 48, D0, 48, 8D, 50, A8, BB, 00, 04, 00, 00, 41, B8, 28, 00, 00, 00, C7, 07, 01, 00, 00, 00, C7, 40, A8, 14, 00, 00, 00, C7, 40, AC, 01, 00, 00, 00, 89, 58, B0, C7, 40, B4, 00, 00, 20, 00, E8, 14, CC, 04, 00, 89, 5C, 24, 68, 8B, 5C, 24, 48, F6, C3, 02, C7, 44, 24, 4C, 01, 00, 00, 00, C7, 44, 24, 58, 00, 00, 02, 00, 48, 8D, 54, 24, 48, 74, 62, 48, 8D...
 
[+]

Entropy:
7.4900

Code size:
366.5 KB (375,296 bytes)

Scan osloadwv.exe - Powered by Reason Core Security