The NETFXSBS10 exe (Microsoft NET Installation Hook) Microsoft Corporation File Malware Analysis
Gridinsoft Logo

The NETFXSBS10.exe (Microsoft .NET Installation Hook) File Analysis

Technical Analysis

File Name NETFXSBS10.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.144.174
Database Version 2023-10-29 00:02:52 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
87,824
File Size (bytes)
2023-10-29
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
35a46b09b9d24c5d016551cbdb4b54c0
SHA1
8ac70f2616eb26e70c3cade0baed3994d9f60a5d
SHA256
246d976fbbbf12bce8e095d490d742378b153f96433e7929e6960c5e7453501c
SHA512
b81db02cf0e15b249cbfe6afc5ce42c3354e8dd5ef079b599701841350c2ebaa255876a59078fcc2003cbdb55bd5b8ab798704234de0d2897c386c436ee472de
ImpHash
101c57b0c9b86bb8d44f712960074bd8

PE Analysis

Basic Information

Image Base 0x10000000
Entry Point 0x100042dc
Compilation Time 2012-02-16 23:52:43
Checksum 0x00018d06 (Actual: 0x00018d06)
OS Version 5.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path NETFXSBS10.pdb
Digital Signature OK
Imports 3 libraries
ADVAPI32, KERNEL32, SHLWAPI
Exports 0 functions
Resources 2 Resources
Sections 4 Sections

Digital Signatures

Microsoft Code Signing PCA Microsoft Corporation (US)
Microsoft Time-Stamp PCA Microsoft Corporation (US)
Microsoft Root Certificate Authority Microsoft Corporation (US)
Microsoft Root Certificate Authority Microsoft Corporation (US)

Version Information

CompanyName Microsoft Corporation
FileDescription Microsoft .NET Installation Hook
FileVersion 4.0.41208.0 (Main.041208-0000)
InternalName NETFXSBS10.exe
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename NETFXSBS10.exe
ProductName Microsoft® .NET Framework
ProductVersion 4.0.41208.0
Comments Flavor=Retail
PrivateBuild DDBLD542
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 66,882 bytes 67,072 bytes 6.57 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 3B89AC49C1BCDF6013594F1FA826527A
.data 0x00012000 11,464 bytes 4,608 bytes 2.19 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3D346D3F2BD09D7778A8C5FE2550B20D
.rsrc 0x00015000 1,588 bytes 2,048 bytes 4.57 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 625A13F1CE6481BD6CBC114174313C93
.reloc 0x00016000 5,858 bytes 6,144 bytes 4.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 3F7DEC3E409C0CFADA2448219104DE5A
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 2 (1,428 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 1,016 bytes
71.1%
RT_MANIFEST 1 412 bytes
28.9%

Certificate Chain Analysis

Certificate #1
Subject Microsoft Corporation
Microsoft Corporation
US
Issuer Microsoft Code Signing PCA
Serial Number 458566884159955876708458
Certificate #2
Subject Microsoft Time-Stamp Service
Microsoft Corporation
US
Issuer Microsoft Time-Stamp PCA
Serial Number 458163166852659596492826
Certificate #3
Subject Microsoft Time-Stamp PCA
Microsoft Corporation
US
Issuer Microsoft Root Certificate Authority
Serial Number 458482885834455929323548
Certificate #4
Subject Microsoft Code Signing PCA
Microsoft Corporation
US
Issuer Microsoft Root Certificate Authority
Serial Number 458457517902179881451532
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware