文件名 | TEKLauncher (1).exe |
文件类型 |
PE32+ executable (GUI) x86-64, for MS Windows
|
扫描器版本 | 1.0.212.174 |
数据库版本 | 2025-03-30 21:00:27 UTC |
我们的扫描器未检测到威胁
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
2d90de0edaa110e958aa125ecabeac30
|
|
SHA1 |
4ad7c9089ee1d4ff1a941613185e8c278de4d5c3
|
|
SHA256 |
240a9f7e23b8822c4f480bcbc2d8fca1bf486817097cb86347a890092baa99b1
|
|
SHA512 |
8b5d7070cfbb8c9ff0d875561305b4fa012743d847be8dc4ce4e807df89169243dcbf6d35714e4a29ca2e1ba13535542702a7ea781ff31928744e733213a2f4d
|
|
ImpHash |
78da59308ee0088a874b4a6cdd7d91bd
|
图标 |
哈希: bb9beb873272a25026bf66d57b68d25d
模糊: 1229ed6e29282087d05fdc764bcbc036 dHash: f8f8f0e8f8f2f0c0 |
映像基址 | 0x140000000 |
入口点 | 0x140014320 |
编译时间 | 2023-03-24 17:42:24 |
校验和 | 0x0032f9b4 (实际: 0x0032f9b4) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32+ executable (GUI) x86-64, for MS Windows
|
PDB 路径 | D:\a\_work\1\s\artifacts\obj\win-x64.Release\corehost\apphost\standalone\apphost.pdb |
数字签名 | Chain verification from CN=Nuclearist (serial:39250072496249749898143963923751766372, sha1:d675c4cc5dfa7241da44fe659936bf503f71b10d) failed: The X.509 certificate provided is self-signed - "Common Name: Nuclearist" |
导入 | 12 库 |
导出 | 0 函数 |
资源 | 11 资源 |
节 | 7 节 |
Translation | 0x0000 0x04b0 |
CompanyName | Nuclearist |
FileDescription | TEKLauncher |
FileVersion | 9.4.84.0 |
InternalName | TEKLauncher.dll |
LegalCopyright | Copyright © 2020-2023 Nuclearist |
OriginalFilename | TEKLauncher.dll |
ProductName | TEK Launcher |
ProductVersion | 9.4.84.0 |
Assembly Version | 9.4.84.0 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
101,500 bytes | 101,888 bytes | 6.33 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
862B6A1DC2A0FE9FFD3D4382727E71E1 |
.rdata |
0x0001a000 |
39,982 bytes | 40,448 bytes | 4.50 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
96A70B765FAAD1FC09D4AB7825301E7C |
.data |
0x00024000 |
5,480 bytes | 2,560 bytes | 2.62 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
0A7F2235243CFB2BAB16CF80984A3C2A |
.pdata |
0x00026000 |
5,460 bytes | 5,632 bytes | 5.12 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A5ACBF7EFBC23A3E2942672429AC01CF |
_RDATA |
0x00028000 |
348 bytes | 512 bytes | 3.34 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A050C22A1FE15371AC99688988E31007 |
.rsrc |
0x00029000 |
184,820 bytes | 184,832 bytes | 7.99 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
FC7D5A53520771A6DF9A3CEDD30A18A2 |
.reloc |
0x00057000 |
840 bytes | 1,024 bytes | 4.88 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
A9F8C5FFC9C3542B19700BF44209BE83 |
1 检测到高熵(≥7.5)的节 - 可能存在打包/加密
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_ICON | 8 | 182,166 字节 | |
RT_GROUP_ICON | 1 | 118 字节 | |
RT_VERSION | 1 | 806 字节 | |
RT_MANIFEST | 1 | 1,073 字节 |
产品 | TEK Launcher |
描述 | TEKLauncher |
文件版本 | 9.4.84.0 |
原始名称 | TEKLauncher.dll |
签名日期 | 10:10 PM 06/03/2023 (734 天前) |
验证状态 | A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider. |
签名者 | Nuclearist |
内部名称 | TEKLauncher.dll |
版权 | Copyright © 2020-2023 Nuclearist |
02 AC 5C 26 6A 0B 40 9B 8F 0B 79 F2 AE 46 25 77
07 B0 41 8D A5 1E 14 8C 33 1B BC DE B7 13 83 23
0B A6 99 C3 81 1B A1 6A BA 92 38 65 BA 32 F7 14
0C 4D 69 72 4B 94 FA 3C 2A 4A 3D 29 07 80 3D 5A
07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A
08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
0E 44 18 E2 DE DE 36 DD 29 74 C3 44 3A FB 5C E5
1D 87 49 FB 82 96 9C B6 4D AA 9A C3 A7 9A 09 64
✓ 此文件已进行数字签名,证书链已验证。
Chain verification from CN=Nuclearist (serial:39250072496249749898143963923751766372, sha1:d675c4cc5dfa7241da44fe659936bf503f71b10d) failed: The X.509 certificate provided is self-signed - "Common Name: Nuclearist"
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要