文件名 | kds3.exe |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
扫描器版本 | 1.0.215.174 |
数据库版本 | 2025-04-24 05:00:18 UTC |
恶意软件家族: Heuristic
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
792d563cece887bda86db73cad20ba35
|
|
SHA1 |
1b713713b0a8ecdf6637475548d5195e40d0b7f4
|
|
SHA256 |
60fb0cb9ba41d636a29be0547c0cd46f0f8374ba47e0b2604f6ab66d84be84a0
|
|
SHA512 |
3a4ed1a4eb2c7682438aaabf802989729c3ae3b85e86e4686ada182f27d57b7cfcf615c4ee92d8d5acbd97fc80aaaba20912fd7833f3c906c20b5ca3f1805bfa
|
|
ImpHash |
111b34f4048626d3fde36e925a6151e3
|
图标 |
哈希: 2ab17cabd963f9e4209b9da4dc72462d
模糊: d19a7def2cf0693ac5fa5f0e9db6fc7f dHash: 4c9e161712328cec |
映像基址 | 0x00400000 |
入口点 | 0x00d7a000 |
编译时间 | 1998-04-22 02:53:33 |
校验和 | 0x0014fe31 (实际: 0x0014fe31) |
操作系统版本 | 4.0 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
数字签名 | Chain verification from CN=Protection Technology\, Ltd., OU=Software Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Protection Technology\, Ltd., L=Moscow, ST=Not present, C=RU (serial:59936359943326187818286869077043090556, sha1:404820d0a0b9f5dbad49c12bce96d66f10feb232) failed: The path could not be validated because intermediate certificate 1 expired 2009-07-15 23:59:59Z |
导入 | 16 库 |
导出 | 0 函数 |
资源 | 7 资源 |
节 | 6 节 |
CompanyName | VZlab Co Ltd |
FileDescription | VZEngine |
FileVersion | 1, 1, 6, 100 |
InternalName | VZEngine |
LegalCopyright | Copyright 2003-2005 VZlab Co Ltd. |
LegalTrademarks | VZlab Co Ltd. |
OriginalFilename | fullscreen.exe |
ProductName | VZEngine |
ProductVersion | 1, 1, 6, 100 |
Translation | 0x0419 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.sforce3 |
0x00001000 |
1,219,040 bytes | 1,219,040 bytes | 8.00 (打包/加密) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
A73B16F81EFE517ACC0057160A6ED8D9 |
.idata |
0x0012b000 |
20 bytes | 20 bytes | 1.66 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D537379D707CB009A1D737CFB1CBBBA1 |
.brick |
0x0012c000 |
8,593,408 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rsrc |
0x0095e000 |
113,640 bytes | 113,640 bytes | 6.92 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
7CFBF32365DEACE7C7E5CC5BC23D54D7 |
.start |
0x0097a000 |
4,096 bytes | 4,096 bytes | 1.35 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
E951F6747F83DB373F0A38A6F673DDCD |
.brick |
0x0097b000 |
86,016 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
1 检测到高熵(≥7.5)的节 - 可能存在打包/加密
1 检测到较高熵(≥6.5)的节 - 可能存在压缩
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_BITMAP | 1 | 107,508 字节 | |
RT_ICON | 1 | 2,216 字节 | |
RT_DIALOG | 3 | 2,582 字节 | |
RT_GROUP_ICON | 1 | 20 字节 | |
RT_VERSION | 1 | 812 字节 |
此文件未进行数字签名。
⚠ 此文件缺少数字签名或证书链无法验证。
执行来自未知来源的未签名文件时请谨慎。
Chain verification from CN=Protection Technology\, Ltd., OU=Software Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Protection Technology\, Ltd., L=Moscow, ST=Not present, C=RU (serial:59936359943326187818286869077043090556, sha1:404820d0a0b9f5dbad49c12bce96d66f10feb232) failed: The path could not be validated because intermediate certificate 1 expired 2009-07-15 23:59:59Z
建议: 验证文件来源并确保它来自可信的发布者.
按照以下步骤完全从系统中移除威胁