File verdict·Decided by the MT AI Engine
Our call

Suspicious

Unsigned 5 KB DLL claims Microsoft in filename but carries no signature and shows no malicious behaviour.

Trust score55Caution
Microsoft.Services.Store.winmd
5.0 KB
45715793b8c8571554bbe4da3dd9
Antivirus engines
0 of 74 flagged
Code signing
Unsigned
Age
First seen 1mo ago
MT AI Engine · Verdict analysis

The reasoning behind this verdict

The MT AI Engine weighs every signal from this scan — antivirus detections, sandbox behaviour, code signing, prevalence and historical matches — to reach a single, evidence-based verdict.

65%Confidence
High
Reasoning

All 74 engines returned clean results with 17 tier-1 engines explicitly marking the sample harmless. Sandbox execution produced only ambient techniques and no malicious host contact. The decisive counter-signal is the brandMismatch flag: the file name asserts Microsoft ownership yet carries no Authenticode signature, violating Microsoft’s standard signing practice. Medium prevalence and an imphash-only RAG match do not override this metadata conflict. The combination of strong engine silence and a clear impersonation indicator places the sample in the borderline-mixed-signals category.

Key signals · 5

Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.

  1. engines.tier1ReportedClean=17 with tier1Malicious=0

  2. brandMismatch.score=75 — claims Microsoft but unsigned

  3. prevalence.classification=medium (800 sources)

  4. similarHashes[0].matchKind=imphash(signerCoMatch=false)

  5. behaviour.offensiveCount=0 and hasMaliciousSandboxVerdict=false

Points in its favour
  • Zero malicious detections across 74 engines
  • 17 tier-1 engines marked clean
  • No malicious sandbox verdict or contacted hosts
Points against
  • Filename claims Microsoft while binary is unsigned (brandMismatch.score=75)
  • Small file size and recent first-seen date (30 days)
Recommended action

Treat as untrusted until a signed Microsoft equivalent can be obtained; avoid deployment in sensitive environments.

What this file does

What it attempted when executed in an isolated sandbox

  • High concern: Hijacks how Windows loads programs so it runs automatically.

  • Moderate concern: Obfuscates or packs its code to avoid detection.

  • Note: Reads your Windows user-account details.

  • Note: Collects details about your system.

Translated from the file's technical behaviour during analysis. It never ran on your device.

What to do now

We couldn't fully clear this file. Treat it with caution.

  1. Don't run it unless you're certain it came from a source you trust.

  2. Check where you got it — an email attachment or a random download link is a red flag.

  3. If you're unsure, delete it. You can always re-download a clean copy from the official source.

  4. If you're still unsure, scan it again in a day or two — detections often catch up on newer files.

Runtime behaviour

What this file did when executed

This file was detonated in 1 sandbox and its runtime behaviour was observed.

MITRE ATT&CK
5

Adversary techniques mapped to the MITRE ATT&CK framework.

T1027· Obfuscated codeT1033· Reads user infoT1082· System reconT1218.011T1574· Execution hijack
Spawned processes
5
$(unnamed)
"C:\Windows\System32\rundll32.exe" "C:\Users\<USER>\Desktop\library.dll",#1
$(unnamed)
C:\Windows\System32\loaddll32.exe loaddll32.exe "C:\Users\user\Desktop\readme.dll"
$(unnamed)
C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
$(unnamed)
C:\Windows\SysWOW64\cmd.exe cmd.exe /C rundll32.exe "C:\Users\user\Desktop\readme.dll",#1
$(unnamed)
C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Users\user\Desktop\readme.dll",#1
Filesystem & mutexes
1
Files written1
  • \Device\ConDrv\\Connect
No researcher-database hits
External threat-intel sources were not collected for this scan.
Antivirus engine breakdown

0 detections across 74 engines

0 malicious0 suspicious74 clean
Tier-117 engines
0flag
Top commercial AVs (low FP rate)
Tier-240 engines
0flag
Mainstream engines with mixed FP rates
Low-trust17 engines
0flag
Heuristic / generic-AI engines (high FP rate)
All 74 engines report this file as clean.
Hash 45715793b8c8… cross-referenced against 74 AV engines via our AV network.
PE forensics

Section entropy & packers

Section-level entropy and packer detection from the PE header. Nothing suspicious here — entropy is within the normal range for unpacked code.

Unpacked
Section entropy2 sections
.text
4.84
.reloc
0.08
0.0Packed threshold 7.28.0
Prevalence

How widely this file has been seen

Moderate prevalence — neither rare nor common. No strong prior applies.

Medium
Unique uploaders
800
Hundreds of people have uploaded this — common.
Total submissions
851
Includes repeat uploads by the same source.
First seen
1mo ago
Jun 19, 2026
Prevalence quadrant
Rare · New
Targeted malware lives here
Common · New
Just-released software
Rare · Old
Niche or internal tooling
Common · Old
Trusted legitimate binaries
File identity

Forensic fingerprint

File biography
First seen (VT)
6/19/2026, 5:25:04 PM
First seen (MalwareBazaar)
Last analysis (VT)
7/19/2026, 2:21:28 AM
Scanned here
7/19/2026, 8:22:56 PM
File name
Microsoft.Services.Store.winmd
Size
5.0 KB
MIME type
(unknown)
Detected type
Win32 DLL
SHA-256
45715793b8c8571554b0bfb4eccc29e2884c16481e1c7dbee78363bbe4da3dd9
MD5
e91e57474dfa91125183c501783f9ff5
SHA-1
c825aee5a545e0d95d931314e3110d682be743e4
PE imphash
dae02f32a21e03ce65412f6e56942daa
First seen (VT)
6/19/2026, 5:25:04 PM
Last analysis (VT)
7/19/2026, 2:21:28 AM
First scan (MalwareTips)
7/19/2026, 8:22:56 PM
Last scan (MalwareTips)
7/19/2026, 8:22:56 PM
Behavior tags
idleassemblypedll
Frequently asked

Safety FAQ

Common questions about Microsoft.Services.Store.winmd, answered from the scan data above.

  • Microsoft.Services.Store.winmd is suspicious — treat it as unsafe until you're sure. 0 of 74 antivirus engines flag it, which isn't a strong consensus but is enough to be cautious. Don't opened it unless you fully trust where it came from, and prefer downloading the software fresh from its official site.
  • Microsoft.Services.Store.winmd is a file, about 5 KB. We identify a file by its cryptographic hash rather than its name, because the same filename can be reused by completely different files — the hash below is the reliable fingerprint.
  • None — all 74 antivirus engines we queried report Microsoft.Services.Store.winmd as clean. That's reassuring, though brand-new malware can briefly evade detection before vendors add signatures, so we also weigh the file's behaviour and reputation.
  • Act quickly. 1) Disconnect the device from the internet to stop the malware communicating or spreading. 2) Run a full scan with reputable anti-malware software (such as Malwarebytes) and quarantine everything it finds. 3) Change your important passwords from a DIFFERENT, clean device — many threats log keystrokes or steal saved credentials. 4) If you bank or shop on this device, watch closely for fraud and alert your bank. 5) For a confirmed infection, the most reliable fix is to back up your personal files and reinstall the operating system for a clean start.
  • To remove Microsoft.Services.Store.winmd: 1) restart into Safe Mode (Safe Mode with Networking if you need to download a tool) so the malware doesn't auto-start. 2) Run a full scan with reputable anti-malware software and let it quarantine or delete the detections. 3) Delete the original Microsoft.Services.Store.winmd file and empty the Recycle Bin/Trash. 4) Check your browser extensions, startup items, and scheduled tasks for anything unfamiliar. 5) Reboot and scan again to confirm it's gone. If detections keep coming back, a clean operating-system reinstall is the most dependable cure.
  • The SHA-256 hash of Microsoft.Services.Store.winmd is 45715793b8c8571554b0bfb4eccc29e2884c16481e1c7dbee78363bbe4da3dd9, and its MD5 is e91e57474dfa91125183c501783f9ff5. This hash is the file's unique fingerprint — two files with the same SHA-256 are identical. Use it to confirm you're looking at exactly this file (not just one with the same name) when comparing against antivirus databases or a download's published checksum.
  • This report reflects the scan run on July 19, 2026. Because a file's hash never changes, the identity of Microsoft.Services.Store.winmd is fixed — but antivirus coverage improves over time, so a file that looks clean today can pick up detections later (and vice-versa). If you need the latest picture, MalwareTips staff can re-run the analysis from scratch.
Community classification

Reviews & malware reports(0)

Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.

Loading…
Loading reports…
Files are processed in a streaming pass-through — MalwareTips never stores the binary on its servers. Only the scan result (hash, detections, verdict) is retained so the next person who scans the same file gets an instant answer. If you ran this file on your computer and are worried, scan your system with an up-to-date antivirus and change critical passwords from a different device.