文件名 | EDRW v13 Activator v2.1 - De!.exe |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
扫描器版本 | 1.0.217.174 |
数据库版本 | 2025-06-06 18:00:24 UTC |
恶意软件家族: AI
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
284182f0388fe891ed6b6a1da5b4196e
|
|
SHA1 |
ee4ffea0eb3ceef561c7b02fbcc11f14a8775027
|
|
SHA256 |
10badd3b49c88ac87ce720c47ccd79f0db4f8125d63b52d328e554fb549c44a8
|
|
SHA512 |
6797010284372abade5b8ad4c7c84bfedc9d40be56f6a159f4e804933038c57954e5b99915230db41f5b4bb0a975352257629bb2963616e7e41fa0346e1befea
|
|
ImpHash |
3ea9c77da2c70a9af0f1ffdeaa76427e
|
图标 |
哈希: 42a22710013d2940131883c110de4bd1
模糊: bfef0d6c79d6edce3c059fe040d432fa dHash: 9669e896b2b2d480 |
映像基址 | 0x00400000 |
入口点 | 0x006305f4 |
编译时间 | 2020-04-22 21:21:05 |
校验和 | 0x0038cbc4 (实际: 0x0038cbc4) |
操作系统版本 | 5.0 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
数字签名 | No valid SignedData structure was found. |
导入 | 11 库 |
导出 | 3 函数 |
资源 | 53 资源 |
节 | 11 节 |
FileVersion | 2.0.0.0 |
ProductVersion | 1.0.0.0 |
ProgramID | com.embarcadero.EaseUS_DRW |
FileDescription | EaseUS_DRW |
ProductName | EaseUS_DRW |
Translation | 0x0409 0x04e4 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
2,281,952 bytes | 2,281,984 bytes | 6.48 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
12259156EB1F0700AC8540564B25AEC7 |
.itext |
0x0022f000 |
5,704 bytes | 6,144 bytes | 6.09 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
428DBD02B48BCC62DE2734A5866CE7D6 |
.data |
0x00231000 |
37,016 bytes | 37,376 bytes | 6.75 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
7688BF05365D691FAF37AA8AD213D008 |
.bss |
0x0023b000 |
26,628 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x00242000 |
12,614 bytes | 12,800 bytes | 5.12 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
A75268841D2276C894B693A1A08C4908 |
.didata |
0x00246000 |
2,924 bytes | 3,072 bytes | 4.10 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
6041A3A577A4BAD0208C6F60BFDF459F |
.edata |
0x00247000 |
156 bytes | 512 bytes | 1.93 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
75C0B5D43524DB85A6C7B24266C6873C |
.tls |
0x00248000 |
72 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rdata |
0x00249000 |
93 bytes | 512 bytes | 1.37 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
597C567CA004669128FD0786F81DD70C |
.reloc |
0x0024a000 |
206,028 bytes | 206,336 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
B050C170017B7FC0D3C4797706A0B776 |
.rsrc |
0x0027d000 |
1,155,808 bytes | 1,156,096 bytes | 2.64 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
9AD868D4296B227D29B4CB0427729D3F |
1 检测到较高熵(≥6.5)的节 - 可能存在压缩
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_CURSOR | 7 | 2,156 字节 | |
RT_ICON | 9 | 562,568 字节 | |
RT_STRING | 23 | 18,568 字节 | |
RT_RCDATA | 4 | 567,011 字节 | |
RT_GROUP_CURSOR | 7 | 140 字节 | |
RT_GROUP_ICON | 1 | 132 字节 | |
RT_VERSION | 1 | 524 字节 | |
RT_MANIFEST | 1 | 1,836 字节 |
此文件未进行数字签名。
⚠ 此文件缺少数字签名或证书链无法验证。
执行来自未知来源的未签名文件时请谨慎。
No valid SignedData structure was found.
建议: 验证文件来源并确保它来自可信的发布者.
按照以下步骤完全从系统中移除威胁