文件名 | RogueKiller_portable64(2)(1).exe |
文件类型 |
PE32+ executable (GUI) x86-64, for MS Windows
|
扫描器版本 | 1.0.218.174 |
数据库版本 | 2025-06-19 00:00:26 UTC |
我们的扫描器未检测到威胁
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
3231767d98f2b0661b0c35b00cdae53a
|
|
SHA1 |
f6f5247b9464c9ab82c3fd0dcc2cab1ddc979632
|
|
SHA256 |
469b867a43ccaff14a945c277e1e598d4a010a11e94a95b56729337a0a9617b9
|
|
SHA512 |
e3851c7ac438424799c030004c293e80450efb0439e8de019d431ded0cab3bb87125b3cc1175e47e8f78545c107228efe1223a623796b4c91e1924dc3ddbba99
|
|
ImpHash |
29b366a9614df5554670d7f5d9369b86
|
图标 |
哈希: 374a174076a3d232207d021b8f85388d
模糊: d2f740df470017271009413b1adc2f32 dHash: f0ce96b2aad4cc71 |
映像基址 | 0x140000000 |
入口点 | 0x14103e9b0 |
编译时间 | 2025-06-04 12:58:23 |
校验和 | 0x02493206 (实际: 0x02493206) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32+ executable (GUI) x86-64, for MS Windows
|
PDB 路径 | E:\Adlice\RogueKillerQt\x64\RelWithDebInfo\RogueKiller.pdb |
数字签名 | OK |
导入 | 25 库 |
导出 | 0 函数 |
资源 | 42 资源 |
节 | 11 节 |
CompanyName | Adlice Software |
FileDescription | Anti-Malware Scan and Removal |
FileVersion | 16.2.2.0 |
InternalName | RogueKiller Anti-Malware |
LegalCopyright | Copyright Adlice Software(C) 2025 |
LegalTrademarks1 | Adlice Software |
LegalTrademarks2 | Adlice Software |
OriginalFilename | Adlice Protect |
ProductName | Adlice Protect |
ProductVersion | 16.2.2.0 |
Translation | 0x040c 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
19,254,132 bytes | 19,254,272 bytes | 6.48 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
9E24B206EE920D3A3A84C509F893EA71 |
.rdata |
0x0125e000 |
11,017,722 bytes | 11,017,728 bytes | 6.53 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8A4AF15B1629D93FF0874733CE3F5013 |
.data |
0x01ce0000 |
607,980 bytes | 318,976 bytes | 3.64 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
9DD0CCC96759F4EE08109474CE42759F |
.pdata |
0x01d75000 |
1,132,896 bytes | 1,133,056 bytes | 6.78 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
513C4B1EAD7C25EDBFAE7395C4039284 |
.tls |
0x01e8a000 |
305 bytes | 512 bytes | 0.02 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
B30464E69ECC4F2C756FA8FF158A38F1 |
.qtmetad |
0x01e8b000 |
1,606 bytes | 2,048 bytes | 4.78 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ
|
824A21E386E1DBBEFBD99D2F485A777B |
.qtmimed |
0x01e8c000 |
322,789 bytes | 323,072 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ
|
2D32D357AB751FFBBB513570C6EE6986 |
.gfids |
0x01edb000 |
524 bytes | 1,024 bytes | 2.56 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8CA5498CF49D4B0F1F7E22F4D172E073 |
_RDATA |
0x01edc000 |
544 bytes | 1,024 bytes | 2.07 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
75C872B557659A0DE9675B523700AFD5 |
.rsrc |
0x01edd000 |
6,103,632 bytes | 6,104,064 bytes | 7.88 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8C305A6B9193278663A89B934F6D4FCD |
.reloc |
0x024b0000 |
116,716 bytes | 116,736 bytes | 5.49 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
DE193B31C43B454DCCEE293A02B0608A |
2 检测到高熵(≥7.5)的节 - 可能存在打包/加密
2 检测到较高熵(≥6.5)的节 - 可能存在压缩
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
BINARY | 25 | 5,188,980 字节 | |
WAVE | 1 | 742,130 字节 | |
RT_ICON | 13 | 168,171 字节 | |
RT_GROUP_ICON | 1 | 188 字节 | |
RT_VERSION | 1 | 960 字节 | |
RT_MANIFEST | 1 | 902 字节 |
产品 | Adlice Protect |
描述 | Anti-Malware Scan and Removal |
文件版本 | 16.2.2.0 |
原始名称 | Adlice Protect |
签名日期 | 01:00 PM 06/04/2025 (16 天前) |
验证状态 | Signed |
签名者 | ADLICE; Sectigo Public Code Signing CA EV R36; Sectigo Public Code Signing Root R46; Sectigo (AAA) |
副签名者 | Sectigo Public Time Stamping Signer R36; Sectigo Public Time Stamping CA R36; Sectigo Public Time Stamping Root R46 |
内部名称 | RogueKiller Anti-Malware |
版权 | Copyright Adlice Software(C) 2025 |
7A 23 AE DA 53 69 96 0F 91 C8 3E 5C F4 C7 E3 3F
33 D7 08 A8 91 40 53 19 E2 A5 BB D3 39 B9 AD 6E
A4 29 3B 6E 1E DD D7 A7 34 08 87 AD 7A 4E B7 24
36 C2 B0 BD 7C 1B 3A E7 A3 B3 DD 36 CB C9 75 68
FF 72 A1 3E 68 C0 CD C5 75 04 B3 F7 11 CB 92 A3
✓ 此文件已进行数字签名,证书链已验证。
OK
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要