文件名 | SDXHelper.exe |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
扫描器版本 | 1.0.195.174 |
数据库版本 | 2024-10-31 11:00:19 UTC |
我们的扫描器未检测到威胁
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
17fa1325a24fa17196892b8b6f52541f
|
|
SHA1 |
017478e0b6673cc71a4a46a10cdfc3b15ff4d678
|
|
SHA256 |
61a1584b99cef1d2988d7bd8bbd581bc1a1bec7eb95cc0833b9c97f3b62f1c7d
|
|
SHA512 |
8abe9f95918134ae9e1f638dd71347d566b323cee0010d621841bf9df8eda10bcf127086303bf8d38aa21b1249d686c80f8d4f32c0e37bbad0d89850c95885f4
|
|
ImpHash |
3b4e7a43605e6c86f10011cf1fd09b97
|
映像基址 | 0x00400000 |
入口点 | 0x00420284 |
编译时间 | 2024-10-15 00:00:20 |
校验和 | 0x00041dca (实际: 0x00041dca) |
操作系统版本 | 6.1 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
PDB 路径 | D:\dbs\el\omr\Target\x86\ship\postc2r\x-none\sdxhelper.pdb lper.pdb 0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
数字签名 | OK |
导入 | 11 库 |
导出 | 0 函数 |
资源 | 2 资源 |
节 | 6 节 |
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Office SDX Helper |
FileVersion | 16.0.18025.20160 |
InternalName | SDXHELPER |
LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
OriginalFilename | SDXHELPER.EXE |
ProductName | Microsoft Office |
ProductVersion | 16.0.18025.20160 |
Translation | 0x0000 0x04e4 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
142,403 bytes | 142,848 bytes | 6.52 (压缩) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
50EBA006FE1BCEC27D06EDAC0388F2F6 |
.rdata |
0x00024000 |
37,552 bytes | 37,888 bytes | 4.77 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
CA1E03F2CFB782C9E470B882CAE422A5 |
.data |
0x0002e000 |
9,408 bytes | 7,168 bytes | 4.96 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D9BFEA3671B624F09F91AF2EE971CC2A |
.c2r |
0x00031000 |
280 bytes | 512 bytes | 2.02 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
0CF16489F60163DAAF091E55440E084D |
.rsrc |
0x00032000 |
2,880 bytes | 3,072 bytes | 3.46 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
0E62C41695EB9AB77F353B48313ADD64 |
.reloc |
0x00033000 |
10,608 bytes | 10,752 bytes | 6.64 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
9FF1A5087FCF1AAD51A5A279801373FF |
2 检测到较高熵(≥6.5)的节 - 可能存在压缩
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_VERSION | 1 | 2,108 字节 | |
RT_MANIFEST | 1 | 610 字节 |
产品 | Microsoft Office |
描述 | Microsoft Office SDX Helper |
文件版本 | 16.0.18025.20160 |
原始名称 | SDXHELPER.EXE |
签名日期 | 05:12 AM 10/15/2024 (254 天前) |
验证状态 | Signed |
签名者 | Microsoft Corporation; Microsoft Code Signing PCA 2010; Microsoft Root Certificate Authority 2010 |
副签名者 | Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA 2010; Microsoft Root Certificate Authority 2010 |
内部名称 | SDXHELPER |
33 00 00 05 A7 B8 8F FB 97 5D 35 84 EC 00 00 00 00 05 A7
61 0C 52 4C 00 00 00 00 00 03
33 00 00 01 F1 B3 45 F5 27 E8 C0 16 D6 00 01 00 00 01 F1
33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15
33 00 00 03 FE 6B CE DA D6 C8 03 03 A3 00 00 00 00 03 FE
61 0E 90 D2 00 00 00 00 00 03
33 00 00 01 F2 3E 32 D7 64 AC 70 91 94 00 01 00 00 01 F2
✓ 此文件已进行数字签名,证书链已验证。
OK
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要