mscorsvc.dll

Description: .NET Runtime Optimization Service

Authors: © Microsoft Corporation. All rights reserved.

Version: 4.8.4320.0

Architecture: 32-bit

Operating System: Windows

SHA256: 08cf340ce99183363c9559205f9a8fc9

File Size: 443.4 KB

Uploaded At: Dec. 1, 2025, 8:48 a.m.

Views: 14

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • CorCreateNGenProcess (Ordinal: 1, Address: 0x3d5f0)
  • CorGetNGenPolicy (Ordinal: 2, Address: 0x3d840)
  • CorGetSvc (Ordinal: 3, Address: 0x8250)
  • CorInitSvcLogger (Ordinal: 4, Address: 0x1c910)
  • CorSetCriticalTaskState (Ordinal: 5, Address: 0x2c4a0)
  • CorStopNonCriticalTask (Ordinal: 6, Address: 0x2c950)
  • CorSvcLog (Ordinal: 7, Address: 0x1ca60)

Imported DLLs & Functions

ADVAPI32.dll
  • ConvertSidToStringSidW (Address: 0x10067028)
  • ConvertStringSidToSidW (Address: 0x10067034)
  • CreateProcessAsUserW (Address: 0x10067040)
  • DeregisterEventSource (Address: 0x10067044)
  • DuplicateTokenEx (Address: 0x10067030)
  • EventWrite (Address: 0x10067050)
  • FreeSid (Address: 0x1006702c)
  • GetLengthSid (Address: 0x1006703c)
  • GetSidSubAuthority (Address: 0x10067060)
  • GetSidSubAuthorityCount (Address: 0x1006705c)
  • GetTokenInformation (Address: 0x10067024)
  • OpenProcessToken (Address: 0x10067020)
  • RegCloseKey (Address: 0x10067004)
  • RegCreateKeyExW (Address: 0x10067054)
  • RegDeleteKeyW (Address: 0x10067008)
  • RegDeleteValueW (Address: 0x10067014)
  • RegEnumKeyExW (Address: 0x10067018)
  • RegEnumValueW (Address: 0x1006701c)
  • RegisterEventSourceW (Address: 0x10067048)
  • RegNotifyChangeKeyValue (Address: 0x10067000)
  • RegOpenKeyExW (Address: 0x10067058)
  • RegQueryValueExW (Address: 0x1006700c)
  • RegSetValueExW (Address: 0x10067010)
  • ReportEventW (Address: 0x1006704c)
  • SetTokenInformation (Address: 0x10067038)
fusion.dll
  • CreateApplicationContext (Address: 0x10067368)
  • CreateAssemblyCache (Address: 0x1006736c)
  • CreateAssemblyNameObject (Address: 0x10067370)
  • InitializeFusion (Address: 0x10067374)
KERNEL32.dll
  • ActivateActCtx (Address: 0x10067170)
  • CloseHandle (Address: 0x100671cc)
  • CreateActCtxW (Address: 0x10067174)
  • CreateDirectoryW (Address: 0x10067090)
  • CreateEventW (Address: 0x100671d0)
  • CreateFileMappingW (Address: 0x1006709c)
  • CreateFileW (Address: 0x1006711c)
  • CreateMutexW (Address: 0x10067148)
  • CreatePipe (Address: 0x100670c4)
  • CreateProcessW (Address: 0x100670e8)
  • CreateSemaphoreW (Address: 0x10067130)
  • CreateThread (Address: 0x100671d8)
  • DeactivateActCtx (Address: 0x1006716c)
  • DebugBreak (Address: 0x10067068)
  • DeleteCriticalSection (Address: 0x1006719c)
  • DeleteFileW (Address: 0x100671b0)
  • EnterCriticalSection (Address: 0x10067188)
  • ExitProcess (Address: 0x100670b0)
  • FileTimeToSystemTime (Address: 0x100671f4)
  • FindClose (Address: 0x100670f8)
  • FindFirstFileW (Address: 0x100671bc)
  • FindNextFileW (Address: 0x10067164)
  • FormatMessageW (Address: 0x1006720c)
  • FreeLibrary (Address: 0x100670cc)
  • GetACP (Address: 0x10067214)
  • GetCommandLineW (Address: 0x100670a8)
  • GetCPInfo (Address: 0x10067218)
  • GetCurrentProcess (Address: 0x10067070)
  • GetCurrentProcessId (Address: 0x100670b8)
  • GetCurrentThreadId (Address: 0x100670e0)
  • GetEnvironmentVariableW (Address: 0x10067080)
  • GetExitCodeProcess (Address: 0x100670ac)
  • GetFileAttributesExW (Address: 0x1006717c)
  • GetFileAttributesW (Address: 0x100671e8)
  • GetFileSize (Address: 0x10067098)
  • GetFileSizeEx (Address: 0x10067180)
  • GetFullPathNameW (Address: 0x100671e4)
  • GetLastError (Address: 0x100671d4)
  • GetLocalTime (Address: 0x100670dc)
  • GetModuleFileNameW (Address: 0x10067100)
  • GetModuleHandleW (Address: 0x10067104)
  • GetProcAddress (Address: 0x100671e0)
  • GetProcessAffinityMask (Address: 0x100671b8)
  • GetProcessHeap (Address: 0x1006721c)
  • GetSystemDirectoryW (Address: 0x100671b4)
  • GetSystemInfo (Address: 0x100671c8)
  • GetSystemPowerStatus (Address: 0x100671dc)
  • GetSystemTime (Address: 0x100671ec)
  • GetSystemTimeAsFileTime (Address: 0x10067184)
  • GetSystemWindowsDirectoryW (Address: 0x100670f4)
  • GetTickCount (Address: 0x10067194)
  • GetVersionExW (Address: 0x10067074)
  • GetWindowsDirectoryW (Address: 0x100670f0)
  • GlobalAlloc (Address: 0x100670c0)
  • GlobalMemoryStatusEx (Address: 0x10067088)
  • HeapAlloc (Address: 0x100671fc)
  • HeapCreate (Address: 0x10067160)
  • HeapDestroy (Address: 0x10067134)
  • HeapFree (Address: 0x100671f8)
  • HeapValidate (Address: 0x10067140)
  • InitializeCriticalSection (Address: 0x10067198)
  • InitializeSListHead (Address: 0x10067108)
  • IsDBCSLeadByte (Address: 0x10067208)
  • IsDebuggerPresent (Address: 0x100671ac)
  • IsProcessorFeaturePresent (Address: 0x10067110)
  • LCMapStringW (Address: 0x10067204)
  • LeaveCriticalSection (Address: 0x1006718c)
  • LoadLibraryExA (Address: 0x100670fc)
  • LoadLibraryExW (Address: 0x100670a4)
  • LocalFree (Address: 0x100670d4)
  • MapViewOfFile (Address: 0x100670a0)
  • MoveFileExW (Address: 0x10067178)
  • MultiByteToWideChar (Address: 0x10067210)
  • OpenEventW (Address: 0x100670b4)
  • OpenProcess (Address: 0x100670c8)
  • OutputDebugStringW (Address: 0x100670e4)
  • QueryPerformanceCounter (Address: 0x1006710c)
  • RaiseException (Address: 0x100670d8)
  • ReadFile (Address: 0x100670bc)
  • ReleaseActCtx (Address: 0x10067168)
  • ReleaseMutex (Address: 0x10067144)
  • ReleaseSemaphore (Address: 0x10067150)
  • ResetEvent (Address: 0x100671a0)
  • SetConsoleCtrlHandler (Address: 0x10067078)
  • SetEnvironmentVariableW (Address: 0x10067084)
  • SetErrorMode (Address: 0x1006708c)
  • SetEvent (Address: 0x10067190)
  • SetLastError (Address: 0x10067094)
  • SetProcessShutdownParameters (Address: 0x1006707c)
  • SetUnhandledExceptionFilter (Address: 0x10067114)
  • SleepEx (Address: 0x1006712c)
  • SystemTimeToFileTime (Address: 0x100671f0)
  • TerminateProcess (Address: 0x1006706c)
  • TlsAlloc (Address: 0x10067138)
  • TlsFree (Address: 0x10067124)
  • TlsGetValue (Address: 0x10067128)
  • TlsSetValue (Address: 0x1006715c)
  • UnhandledExceptionFilter (Address: 0x10067118)
  • UnmapViewOfFile (Address: 0x100670d0)
  • VerifyVersionInfoW (Address: 0x100671c0)
  • VerSetConditionMask (Address: 0x100671c4)
  • VirtualAlloc (Address: 0x1006714c)
  • VirtualFree (Address: 0x10067154)
  • VirtualProtect (Address: 0x10067158)
  • VirtualQuery (Address: 0x10067120)
  • WaitForMultipleObjects (Address: 0x100671a8)
  • WaitForSingleObject (Address: 0x100671a4)
  • WaitForSingleObjectEx (Address: 0x1006713c)
  • WideCharToMultiByte (Address: 0x10067200)
  • WriteFile (Address: 0x100670ec)
mscoree.dll
  • CLRCreateInstance (Address: 0x10067358)
  • CreateConfigStream (Address: 0x10067354)
  • GetRequestedRuntimeInfo (Address: 0x1006735c)
  • GetXMLObject (Address: 0x10067360)
ole32.dll
  • CoAddRefServerProcess (Address: 0x10067304)
  • CoCreateGuid (Address: 0x100672fc)
  • CoCreateInstance (Address: 0x100672f4)
  • CoDisconnectObject (Address: 0x100672f8)
  • CoInitializeEx (Address: 0x10067314)
  • CoReleaseServerProcess (Address: 0x10067300)
  • CoTaskMemFree (Address: 0x10067308)
  • CoUninitialize (Address: 0x10067318)
  • CoUnmarshalInterface (Address: 0x10067310)
  • CreateStreamOnHGlobal (Address: 0x1006730c)
OLEAUT32.dll
  • SafeArrayCreateVector (Address: 0x10067324)
  • SafeArrayDestroy (Address: 0x10067330)
  • SafeArrayGetElement (Address: 0x10067328)
  • SafeArrayGetUBound (Address: 0x1006732c)
  • SafeArrayPutElement (Address: 0x10067320)
  • SetErrorInfo (Address: 0x10067344)
  • SysAllocString (Address: 0x1006734c)
  • SysFreeString (Address: 0x10067348)
  • SysStringLen (Address: 0x10067334)
  • VariantChangeType (Address: 0x10067338)
  • VariantClear (Address: 0x1006733c)
  • VariantInit (Address: 0x10067340)
ucrtbase_clr0400.dll
  • __acrt_iob_func (Address: 0x1006728c)
  • __stdio_common_vfwprintf (Address: 0x10067284)
  • __stdio_common_vsnprintf_s (Address: 0x1006727c)
  • __stdio_common_vsnwprintf_s (Address: 0x10067280)
  • __stdio_common_vswprintf_s (Address: 0x1006729c)
  • _cexit (Address: 0x100672d0)
  • _configure_narrow_argv (Address: 0x100672b8)
  • _crt_atexit (Address: 0x100672cc)
  • _errno (Address: 0x10067270)
  • _execute_onexit_table (Address: 0x100672c8)
  • _flushall (Address: 0x1006725c)
  • _initialize_narrow_environment (Address: 0x100672bc)
  • _initialize_onexit_table (Address: 0x100672c0)
  • _initterm (Address: 0x1006726c)
  • _initterm_e (Address: 0x100672b0)
  • _putws (Address: 0x10067258)
  • _register_onexit_function (Address: 0x100672c4)
  • _seh_filter_dll (Address: 0x100672b4)
  • _wcsicmp (Address: 0x100672a4)
  • _wcsnicmp (Address: 0x10067298)
  • _wtoi (Address: 0x100672a0)
  • fflush (Address: 0x10067288)
  • free (Address: 0x100672d8)
  • iswspace (Address: 0x10067268)
  • malloc (Address: 0x10067254)
  • strcpy_s (Address: 0x10067278)
  • strncmp (Address: 0x10067274)
  • wcscat_s (Address: 0x10067264)
  • wcscpy_s (Address: 0x10067294)
  • wcsncmp (Address: 0x100672d4)
  • wcsncpy_s (Address: 0x10067290)
  • wcstok_s (Address: 0x10067260)
  • wcstol (Address: 0x100672a8)
  • wcstoul (Address: 0x100672ac)
USER32.dll
  • GetProcessWindowStation (Address: 0x100672e0)
  • GetUserObjectInformationW (Address: 0x100672e8)
  • LoadStringW (Address: 0x100672ec)
  • SystemParametersInfoW (Address: 0x100672e4)
VCRUNTIME140_CLR0400.dll
  • __CxxFrameHandler3 (Address: 0x10067234)
  • __std_type_info_destroy_list (Address: 0x1006722c)
  • _CxxThrowException (Address: 0x10067240)
  • _except_handler4_common (Address: 0x10067230)
  • _purecall (Address: 0x1006723c)
  • memcpy (Address: 0x10067224)
  • memmove (Address: 0x10067238)
  • memset (Address: 0x10067228)
  • wcschr (Address: 0x10067248)
  • wcsrchr (Address: 0x10067244)
  • wcsstr (Address: 0x1006724c)