mscorsvc.dll
Description: .NET Runtime Optimization Service
Authors: © Microsoft Corporation. All rights reserved.
Version: 4.8.4084.0
Architecture: 32-bit
Operating System: Windows
SHA256: 74d2e5075cf6ac7809641955cac7912e
File Size: 450.8 KB
Uploaded At: Dec. 1, 2025, 8:48 a.m.
Views: 14
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- CorCreateNGenProcess (Ordinal: 1, Address: 0x3d5d0)
- CorGetNGenPolicy (Ordinal: 2, Address: 0x3d820)
- CorGetSvc (Ordinal: 3, Address: 0x102a0)
- CorInitSvcLogger (Ordinal: 4, Address: 0x1c8f0)
- CorSetCriticalTaskState (Ordinal: 5, Address: 0x2c480)
- CorStopNonCriticalTask (Ordinal: 6, Address: 0x2c930)
- CorSvcLog (Ordinal: 7, Address: 0x1ca40)
Imported DLLs & Functions
ADVAPI32.dll
- ConvertSidToStringSidW (Address: 0x10067028)
- ConvertStringSidToSidW (Address: 0x10067034)
- CreateProcessAsUserW (Address: 0x10067040)
- DeregisterEventSource (Address: 0x10067044)
- DuplicateTokenEx (Address: 0x10067030)
- EventWrite (Address: 0x10067050)
- FreeSid (Address: 0x1006702c)
- GetLengthSid (Address: 0x1006703c)
- GetSidSubAuthority (Address: 0x10067060)
- GetSidSubAuthorityCount (Address: 0x1006705c)
- GetTokenInformation (Address: 0x10067024)
- OpenProcessToken (Address: 0x10067020)
- RegCloseKey (Address: 0x10067004)
- RegCreateKeyExW (Address: 0x10067054)
- RegDeleteKeyW (Address: 0x10067008)
- RegDeleteValueW (Address: 0x10067014)
- RegEnumKeyExW (Address: 0x10067018)
- RegEnumValueW (Address: 0x1006701c)
- RegisterEventSourceW (Address: 0x10067048)
- RegNotifyChangeKeyValue (Address: 0x10067000)
- RegOpenKeyExW (Address: 0x10067058)
- RegQueryValueExW (Address: 0x1006700c)
- RegSetValueExW (Address: 0x10067010)
- ReportEventW (Address: 0x1006704c)
- SetTokenInformation (Address: 0x10067038)
fusion.dll
- CreateApplicationContext (Address: 0x10067368)
- CreateAssemblyCache (Address: 0x1006736c)
- CreateAssemblyNameObject (Address: 0x10067370)
- InitializeFusion (Address: 0x10067374)
KERNEL32.dll
- ActivateActCtx (Address: 0x10067170)
- CloseHandle (Address: 0x100671cc)
- CreateActCtxW (Address: 0x10067174)
- CreateDirectoryW (Address: 0x10067090)
- CreateEventW (Address: 0x100671d0)
- CreateFileMappingW (Address: 0x1006709c)
- CreateFileW (Address: 0x1006711c)
- CreateMutexW (Address: 0x10067148)
- CreatePipe (Address: 0x100670c4)
- CreateProcessW (Address: 0x100670e8)
- CreateSemaphoreW (Address: 0x10067130)
- CreateThread (Address: 0x100671d8)
- DeactivateActCtx (Address: 0x1006716c)
- DebugBreak (Address: 0x10067068)
- DeleteCriticalSection (Address: 0x1006719c)
- DeleteFileW (Address: 0x100671b0)
- EnterCriticalSection (Address: 0x10067188)
- ExitProcess (Address: 0x100670b0)
- FileTimeToSystemTime (Address: 0x100671f4)
- FindClose (Address: 0x100670f8)
- FindFirstFileW (Address: 0x100671bc)
- FindNextFileW (Address: 0x10067164)
- FormatMessageW (Address: 0x1006720c)
- FreeLibrary (Address: 0x100670cc)
- GetACP (Address: 0x10067214)
- GetCommandLineW (Address: 0x100670a8)
- GetCPInfo (Address: 0x10067218)
- GetCurrentProcess (Address: 0x10067070)
- GetCurrentProcessId (Address: 0x100670b8)
- GetCurrentThreadId (Address: 0x100670e0)
- GetEnvironmentVariableW (Address: 0x10067080)
- GetExitCodeProcess (Address: 0x100670ac)
- GetFileAttributesExW (Address: 0x1006717c)
- GetFileAttributesW (Address: 0x100671e8)
- GetFileSize (Address: 0x10067098)
- GetFileSizeEx (Address: 0x10067180)
- GetFullPathNameW (Address: 0x100671e4)
- GetLastError (Address: 0x100671d4)
- GetLocalTime (Address: 0x100670dc)
- GetModuleFileNameW (Address: 0x10067100)
- GetModuleHandleW (Address: 0x10067104)
- GetProcAddress (Address: 0x100671e0)
- GetProcessAffinityMask (Address: 0x100671b8)
- GetProcessHeap (Address: 0x1006721c)
- GetSystemDirectoryW (Address: 0x100671b4)
- GetSystemInfo (Address: 0x100671c8)
- GetSystemPowerStatus (Address: 0x100671dc)
- GetSystemTime (Address: 0x100671ec)
- GetSystemTimeAsFileTime (Address: 0x10067184)
- GetSystemWindowsDirectoryW (Address: 0x100670f4)
- GetTickCount (Address: 0x10067194)
- GetVersionExW (Address: 0x10067074)
- GetWindowsDirectoryW (Address: 0x100670f0)
- GlobalAlloc (Address: 0x100670c0)
- GlobalMemoryStatusEx (Address: 0x10067088)
- HeapAlloc (Address: 0x100671fc)
- HeapCreate (Address: 0x10067160)
- HeapDestroy (Address: 0x10067134)
- HeapFree (Address: 0x100671f8)
- HeapValidate (Address: 0x10067140)
- InitializeCriticalSection (Address: 0x10067198)
- InitializeSListHead (Address: 0x10067108)
- IsDBCSLeadByte (Address: 0x10067208)
- IsDebuggerPresent (Address: 0x100671ac)
- IsProcessorFeaturePresent (Address: 0x10067110)
- LCMapStringW (Address: 0x10067204)
- LeaveCriticalSection (Address: 0x1006718c)
- LoadLibraryExA (Address: 0x100670fc)
- LoadLibraryExW (Address: 0x100670a4)
- LocalFree (Address: 0x100670d4)
- MapViewOfFile (Address: 0x100670a0)
- MoveFileExW (Address: 0x10067178)
- MultiByteToWideChar (Address: 0x10067210)
- OpenEventW (Address: 0x100670b4)
- OpenProcess (Address: 0x100670c8)
- OutputDebugStringW (Address: 0x100670e4)
- QueryPerformanceCounter (Address: 0x1006710c)
- RaiseException (Address: 0x100670d8)
- ReadFile (Address: 0x100670bc)
- ReleaseActCtx (Address: 0x10067168)
- ReleaseMutex (Address: 0x10067144)
- ReleaseSemaphore (Address: 0x10067150)
- ResetEvent (Address: 0x100671a0)
- SetConsoleCtrlHandler (Address: 0x10067078)
- SetEnvironmentVariableW (Address: 0x10067084)
- SetErrorMode (Address: 0x1006708c)
- SetEvent (Address: 0x10067190)
- SetLastError (Address: 0x10067094)
- SetProcessShutdownParameters (Address: 0x1006707c)
- SetUnhandledExceptionFilter (Address: 0x10067114)
- SleepEx (Address: 0x1006712c)
- SystemTimeToFileTime (Address: 0x100671f0)
- TerminateProcess (Address: 0x1006706c)
- TlsAlloc (Address: 0x10067138)
- TlsFree (Address: 0x10067124)
- TlsGetValue (Address: 0x10067128)
- TlsSetValue (Address: 0x1006715c)
- UnhandledExceptionFilter (Address: 0x10067118)
- UnmapViewOfFile (Address: 0x100670d0)
- VerifyVersionInfoW (Address: 0x100671c0)
- VerSetConditionMask (Address: 0x100671c4)
- VirtualAlloc (Address: 0x1006714c)
- VirtualFree (Address: 0x10067154)
- VirtualProtect (Address: 0x10067158)
- VirtualQuery (Address: 0x10067120)
- WaitForMultipleObjects (Address: 0x100671a8)
- WaitForSingleObject (Address: 0x100671a4)
- WaitForSingleObjectEx (Address: 0x1006713c)
- WideCharToMultiByte (Address: 0x10067200)
- WriteFile (Address: 0x100670ec)
mscoree.dll
- CLRCreateInstance (Address: 0x10067358)
- CreateConfigStream (Address: 0x10067354)
- GetRequestedRuntimeInfo (Address: 0x1006735c)
- GetXMLObject (Address: 0x10067360)
ole32.dll
- CoAddRefServerProcess (Address: 0x10067304)
- CoCreateGuid (Address: 0x100672fc)
- CoCreateInstance (Address: 0x100672f4)
- CoDisconnectObject (Address: 0x100672f8)
- CoInitializeEx (Address: 0x10067314)
- CoReleaseServerProcess (Address: 0x10067300)
- CoTaskMemFree (Address: 0x10067308)
- CoUninitialize (Address: 0x10067318)
- CoUnmarshalInterface (Address: 0x10067310)
- CreateStreamOnHGlobal (Address: 0x1006730c)
OLEAUT32.dll
- SafeArrayCreateVector (Address: 0x10067324)
- SafeArrayDestroy (Address: 0x10067330)
- SafeArrayGetElement (Address: 0x10067328)
- SafeArrayGetUBound (Address: 0x1006732c)
- SafeArrayPutElement (Address: 0x10067320)
- SetErrorInfo (Address: 0x10067344)
- SysAllocString (Address: 0x1006734c)
- SysFreeString (Address: 0x10067348)
- SysStringLen (Address: 0x10067334)
- VariantChangeType (Address: 0x10067338)
- VariantClear (Address: 0x1006733c)
- VariantInit (Address: 0x10067340)
ucrtbase_clr0400.dll
- __acrt_iob_func (Address: 0x1006728c)
- __stdio_common_vfwprintf (Address: 0x10067284)
- __stdio_common_vsnprintf_s (Address: 0x1006727c)
- __stdio_common_vsnwprintf_s (Address: 0x10067280)
- __stdio_common_vswprintf_s (Address: 0x1006729c)
- _cexit (Address: 0x100672d0)
- _configure_narrow_argv (Address: 0x100672b8)
- _crt_atexit (Address: 0x100672cc)
- _errno (Address: 0x10067270)
- _execute_onexit_table (Address: 0x100672c8)
- _flushall (Address: 0x1006725c)
- _initialize_narrow_environment (Address: 0x100672bc)
- _initialize_onexit_table (Address: 0x100672c0)
- _initterm (Address: 0x1006726c)
- _initterm_e (Address: 0x100672b0)
- _putws (Address: 0x10067258)
- _register_onexit_function (Address: 0x100672c4)
- _seh_filter_dll (Address: 0x100672b4)
- _wcsicmp (Address: 0x100672a4)
- _wcsnicmp (Address: 0x10067298)
- _wtoi (Address: 0x100672a0)
- fflush (Address: 0x10067288)
- free (Address: 0x100672d8)
- iswspace (Address: 0x10067268)
- malloc (Address: 0x10067254)
- strcpy_s (Address: 0x10067278)
- strncmp (Address: 0x10067274)
- wcscat_s (Address: 0x10067264)
- wcscpy_s (Address: 0x10067294)
- wcsncmp (Address: 0x100672d4)
- wcsncpy_s (Address: 0x10067290)
- wcstok_s (Address: 0x10067260)
- wcstol (Address: 0x100672a8)
- wcstoul (Address: 0x100672ac)
USER32.dll
- GetProcessWindowStation (Address: 0x100672e0)
- GetUserObjectInformationW (Address: 0x100672e8)
- LoadStringW (Address: 0x100672ec)
- SystemParametersInfoW (Address: 0x100672e4)
VCRUNTIME140_CLR0400.dll
- __CxxFrameHandler3 (Address: 0x10067234)
- __std_type_info_destroy_list (Address: 0x1006722c)
- _CxxThrowException (Address: 0x10067240)
- _except_handler4_common (Address: 0x10067230)
- _purecall (Address: 0x1006723c)
- memcpy (Address: 0x10067224)
- memmove (Address: 0x10067238)
- memset (Address: 0x10067228)
- wcschr (Address: 0x10067248)
- wcsrchr (Address: 0x10067244)
- wcsstr (Address: 0x1006724c)