Online Virus Checker | v.1.0.187.174 |
DB Version: | 2024-09-10 08:00:25 |
File | RuntimeBroker.exe |
Checked | 2024-09-10 06:06:48 |
MD5 | 76fad25855456def36d7afbae79db05c |
SHA1 | 953fb3d50404336d9e3b220fd15f770e90a369a0 |
SHA256 | 2eb209852198689a3f4bae01d95f23d6fec77d4224bfa704eecf460aa7343a5e |
SHA512 | 5630c1735b9425958bdc38670e2149a5a15af9ec874163f2063734d1f477c2ee7a1a4d6c4fcb21e94e0d2238f4cdcaff660c806afa86df90d0f09a5094b8e251 |
Imphash | ddae2f228a3cb382bc043f060553ed21 |
File Size | 133656 bytes |
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
CompanyName | Microsoft Corporation |
FileDescription | Runtime Broker |
FileVersion | 10.0.22621.3672 (WinBuild.160101.0800) |
InternalName | RuntimeBroker.exe |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | RuntimeBroker.exe |
ProductName | Microsoft® Windows® Operating System |
ProductVersion | 10.0.22621.3672 |
Translation | 0x0409 0x04b0 |
Image Base: | 0x140000000 |
Entry Point: | 0x140004c90 |
Compilation: | 2082-10-02 21:17:26 |
Checksum: | 0x0002656a (Actual: 0x0002656a) |
OS Version: | 10.0 |
PDB Path: | RuntimeBroker.pdb |
PEiD: | PE32+ executable (GUI) x86-64, for MS Windows |
Sign: | OK |
Sections: | 8 |
Imports: | api-ms-win-crt-runtime-l1-1-0, api-ms-win-crt-private-l1-1-0, api-ms-win-crt-string-l1-1-0, ntdll, api-ms-win-security-base-l1-1-0, api-ms-win-core-libraryloader-l1-2-0, api-ms-win-core-synch-l1-2-0, api-ms-win-core-registry-l1-1-0, api-ms-win-core-synch-l1-1-0, api-ms-win-core-heap-l1-1-0, api-ms-win-core-errorhandling-l1-1-0, api-ms-win-core-processthreads-l1-1-0, api-ms-win-core-synch-l1-2-1, api-ms-win-eventing-provider-l1-1-0, api-ms-win-core-processthreads-l1-1-1, api-ms-win-core-threadpool-l1-2-0, api-ms-win-core-localization-l1-2-0, api-ms-win-core-debug-l1-1-0, api-ms-win-core-handle-l1-1-0, api-ms-win-core-heap-l2-1-0, api-ms-win-core-psapi-l1-1-0, api-ms-win-core-profile-l1-1-0, api-ms-win-core-sysinfo-l1-1-0, api-ms-win-core-interlocked-l1-1-0, api-ms-win-core-apiquery-l1-1-0, msvcp_win, api-ms-win-core-delayload-l1-1-1, api-ms-win-core-delayload-l1-1-0, api-ms-win-core-memory-l1-1-0, |
Exports: | 0 |
Resources: | 2 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0000ff8e | 0x00010000 | ffacc7a6d346137162b4f16be591ed37 | 6.25 |
.imrsiv | 0x00011000 | 0x00000004 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.rdata | 0x00012000 | 0x00006a7e | 0x00007000 | 064da2264220f828ef1f7c657e0e43b8 | 4.69 |
.data | 0x00019000 | 0x00000dd8 | 0x00001000 | ba717a5a8356a69789378c8af03dabb7 | 0.19 |
.pdata | 0x0001a000 | 0x0000147c | 0x00002000 | 8becac9af16ec18847d6271f9edbc53c | 3.54 |
.didat | 0x0001c000 | 0x00000188 | 0x00001000 | b434d2ec6da998890a72073240c1948d | 0.38 |
.rsrc | 0x0001d000 | 0x00000958 | 0x00001000 | 43440bd8cd1c3047fe88697513483d78 | 3.27 |
.reloc | 0x0001e000 | 0x000001cc | 0x00001000 | 0d9703432a10c34c238c6966a22a43b7 | 0.99 |