文件名 | uplay_r1_loader64.dll |
文件类型 |
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
扫描器版本 | 1.0.215.174 |
数据库版本 | 2025-04-29 18:00:20 UTC |
恶意软件家族: Agent
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
5ae834406f14cfbc0a4eda72edc5c4a2
|
|
SHA1 |
4bbe8036b3f4a9eea0a00a1bca108d6baff2d965
|
|
SHA256 |
559e53376e84bd757a827b9b9c0976748c2fd6218b0d2c8432024527833b1d2e
|
|
SHA512 |
6508b8a5ec9dbc101f9869a45b4c33ac472e6c30aff745eadf4a887fd482960f3137c0eef06132f7e786d4ad3af756aecf47b0da6af2de911f47ea0dd507b672
|
|
ImpHash |
9c0057044059368de27895c57e9ef776
|
映像基址 | 0x180000000 |
入口点 | 0x1800011c0 |
编译时间 | 2014-06-25 21:53:46 |
校验和 | 0x00000000 (实际: 0x000217e2) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
数字签名 | No valid SignedData structure was found. |
导入 |
1 库
KERNEL32 |
导出 | 89 函数 |
资源 | 1 资源 |
节 | 6 节 |
CompanyName | *!ReLOADeD!* |
FileDescription | UPlay |
FileVersion | 2,0,0,0 |
InternalName | uplay* |
LegalCopyright | *!ReLOADeD!* |
OriginalFilename | uplay* |
ProductName | UPlay |
ProductVersion | 2,0,0,0 |
Translation | 0x0409 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
29,300 bytes | 29,696 bytes | 6.22 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
8F15E1CE948EA5791BD809CBC438B6A3 |
.rdata |
0x00009000 |
31,235 bytes | 31,744 bytes | 4.46 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
E17195D42334378A06D404A78D592E9C |
.data |
0x00011000 |
13,920 bytes | 5,120 bytes | 1.84 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
5A37B3DCA8879E2C91A88A47F70EF4E2 |
.pdata |
0x00015000 |
1,920 bytes | 2,048 bytes | 4.20 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
57D3C96CB825D583053C9C3B46D74DDB |
.rsrc |
0x00016000 |
744 bytes | 1,024 bytes | 2.43 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
645EA528C98571781A3332255342C12C |
.reloc |
0x00017000 |
3,150 bytes | 3,584 bytes | 2.81 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
C23B6E567E96C9D37E420D018F0EC93D |
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_VERSION | 1 | 644 字节 |
此文件未进行数字签名。
⚠ 此文件缺少数字签名或证书链无法验证。
执行来自未知来源的未签名文件时请谨慎。
No valid SignedData structure was found.
建议: 验证文件来源并确保它来自可信的发布者.
按照以下步骤完全从系统中移除威胁