文件名 | FLEngine_x64_Copy5.dll |
文件类型 |
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
扫描器版本 | 1.0.179.174 |
数据库版本 | 2024-06-16 07:00:21 UTC |
恶意软件家族: Heuristic
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
06bb6dde5c9adbac93470ed86ce7d5ff
|
|
SHA1 |
46fc43590d6d4c4f04f23ab0eb6f8f602e7e731a
|
|
SHA256 |
2a44a8af200c4ee36de4b0f91471ffca82ce25e0fe90401d64a9d4c01b9f9525
|
|
SHA512 |
5399dbdf1c523ae86956b3a774996cbe0276fb1ca08919564f7669e8cb695711dc9830cbf751cf4479d2bb08f982193c22e00a8be34c5466c9567287a45d8c23
|
|
ImpHash |
c995c6a83354266523555dc8622edb0c
|
图标 |
哈希: 0ae26ef28b4d6932e1e5c1be6e312dfe
模糊: 65c101bdf2d311ed3fbfd74fba495bcb dHash: f8f87879793998e8 |
映像基址 | 0x00400000 |
入口点 | 0x0415a454 |
编译时间 | 2024-02-05 14:03:41 |
校验和 | 0x03f5080f (实际: 0x03f5080f) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
数字签名 | Chain verification from CN=Image Line (serial:-134698403968793511265905581838736896500, sha1:bbc705d3179ba1cdde5afb573345260b0fb6d31c) failed: The X.509 certificate provided is self-signed - "Common Name: Image Line" |
导入 | 23 库 |
导出 | 4 函数 |
资源 | 313 资源 |
节 | 20 节 |
CompanyName | Image-Line |
FileDescription | FL Studio engine |
FileVersion | 21.2.3.4004 |
InternalName | FL Studio |
LegalCopyright | Copyright (c) 1997-2024 by Image-Line. All rights reserved. |
ProductName | FL Studio |
ProductVersion | 21.2.3.4004 |
Translation | 0x0409 0x04e4 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
13,972,700 bytes | 13,972,992 bytes | 6.08 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
FA3E6C23C4DDB61204029E45180C26FA |
.data |
0x00d55000 |
1,900,416 bytes | 1,900,544 bytes | 6.12 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
FAE57E941715EC600A902FDCBE074C3C |
.bss |
0x00f25000 |
1,293,176 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x01061000 |
26,030 bytes | 26,112 bytes | 7.90 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
B7ECF4DCE8C2A9777FF079A190340D52 |
.didata |
0x01068000 |
4,592 bytes | 4,608 bytes | 3.54 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
F9EE01F0540DB2F33A39D80A22A0E5F9 |
.edata |
0x0106a000 |
189 bytes | 512 bytes | 2.46 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
BCC2F2523748DEA72C5E6E4063DAA69C |
.rdata |
0x0106b000 |
69 bytes | 512 bytes | 1.19 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
19AB6A27AEE54F4CC5376359F1D9573B |
.xda0 |
0x0106c000 |
468,224 bytes | 468,480 bytes | 7.96 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
D602D8C282EFDBA331C1E0CE54738C3B |
.pdata |
0x010df000 |
572,988 bytes | 573,440 bytes | 7.96 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
6D107F3F3F8A51E99059C45D165A898C |
.xda1 |
0x0116b000 |
37,256,968 bytes | 37,257,216 bytes | 7.94 (打包/加密) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
A166BF416952605CE4D094AA5C5D2DDE |
.xda2 |
0x034f3000 |
6,848 bytes | 7,168 bytes | 0.21 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D19A7495B0CA3BAB5DF98A19D8B3CB15 |
.xda3 |
0x034f5000 |
5,101,464 bytes | 5,101,568 bytes | 7.66 (打包/加密) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
F562AB6A498300051E11BD8A7A3F37FF |
.xda0 |
0x039d3000 |
468,680 bytes | 468,992 bytes | 7.91 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
FAD05F92623E1D206AD010424ED5CEEA |
.xda1 |
0x03a46000 |
1,832,885 bytes | 1,832,960 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
F0DE6625E2653E2C305AD8AAA7FEE654 |
.xda0 |
0x03c06000 |
1,536 bytes | 1,536 bytes | 7.11 (压缩) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
40365449C0B02B9A45816BA3C3E22D06 |
.xda2 |
0x03c07000 |
600,536 bytes | 600,576 bytes | 7.09 (压缩) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
14109D880A5A0D79450C2C4098E84AAB |
.xda3 |
0x03c9a000 |
2,176 bytes | 2,560 bytes | 2.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
414F6A2224A32ECD5A7213B61A7B4A7C |
.xda4 |
0x03c9b000 |
1,791,452 bytes | 1,791,488 bytes | 7.47 (压缩) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_NOT_PAGED|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
A141C5FC7E8B24F9CDCD2510C4BA0777 |
.reloc |
0x03e51000 |
480,080 bytes | 480,256 bytes | 6.35 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
57BA22487132D3418BE629EA2F15CE48 |
.rsrc |
0x03ec7000 |
1,832,885 bytes | 1,832,960 bytes | 6.13 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
DE8BF6C30AA77D29CB7EC4C6F5BDA9F0 |
7 检测到高熵(≥7.5)的节 - 可能存在打包/加密
3 检测到较高熵(≥6.5)的节 - 可能存在压缩
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_CURSOR | 60 | 154,880 字节 | |
RT_BITMAP | 25 | 44,750 字节 | |
RT_ICON | 13 | 100,055 字节 | |
RT_DIALOG | 1 | 82 字节 | |
RT_STRING | 39 | 38,196 字节 | |
RT_RCDATA | 115 | 1,470,581 字节 | |
RT_GROUP_CURSOR | 57 | 1,140 字节 | |
RT_GROUP_ICON | 1 | 188 字节 | |
RT_VERSION | 1 | 728 字节 | |
RT_MANIFEST | 1 | 1,197 字节 |
此文件未进行数字签名。
⚠ 此文件缺少数字签名或证书链无法验证。
执行来自未知来源的未签名文件时请谨慎。
Chain verification from CN=Image Line (serial:-134698403968793511265905581838736896500, sha1:bbc705d3179ba1cdde5afb573345260b0fb6d31c) failed: The X.509 certificate provided is self-signed - "Common Name: Image Line"
建议: 验证文件来源并确保它来自可信的发布者.
按照以下步骤完全从系统中移除威胁