_shfoldr.dll

Shell Folder Service

Microsoft Corporation

Publisher:
Microsoft Corporation

Product:
Microsoft® Windows® Operating System

Description:
Shell Folder Service

Version:
6.00.2800.1106 (xpsp1.020828-1920)

MD5:
33c369a535290299ed5e5167cea37fdc

SHA-1:
4ea387cb55cada35de02738dfb324ab830d416f4

SHA-256:
e69da5febb5a2932cbe731e32a5d7f6615bb987a119ef2cedead4555d86144e8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 3:01:40 PM UTC  (today)

File size:
22 KB (22,528 bytes)

Product version:
6.00.2800.1106

Copyright:
© Microsoft Corporation. All rights reserved.

Original file name:
shfolder.dll

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\_shfoldr.dll

File PE Metadata
Compilation timestamp:
8/29/2002 6:43:06 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
7.0

CTPH (ssdeep):
384:kqXjRYAhfBALfdpju122HoSHigH2euwsHTGHVb+d3HmnH+aHjHqLHxmoqQG0CHuz:kWjRLhZAL7juAL4+

Entry address:
0x10C4

Entry point:
8B, 44, 24, 08, 48, 75, 13, 56, 8B, 74, 24, 08, 56, FF, 15, 28, 10, 73, 76, 89, 35, 00, 30, 73, 76, 5E, 33, C0, 40, C2, 0C, 00, 55, 8B, EC, 57, 8B, 7D, 18, 68, 08, 02, 00, 00, 57, FF, 15, 44, 10, 73, 76, 85, C0, 0F, 85, 29, 01, 00, 00, 66, 83, 27, 00, 53, 8B, 5D, 0C, 56, 57, FF, 75, 14, FF, 75, 10, 53, FF, 75, 08, E8, 1F, 00, 00, 00, 3D, 01, 40, 00, 80, B9, 57, 00, 07, 80, 0F, 84, 0A, 01, 00, 00, 3B, C1, 0F, 84, 02, 01, 00, 00, 5E, 5B, 5F, 5D, C2, 14, 00, 55, 8B, EC, 56, 57, 68, 98, 11, 73, 76, BF, 01, 40...
 
[+]

Entropy:
4.7972

Code size:
8 KB (8,192 bytes)

The file _shfoldr.dll has been seen being distributed by the following URL.

Scan _shfoldr.dll - Powered by Reason Core Security