文件名 | Setup.exe |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
扫描器版本 | 1.0.217.174 |
数据库版本 | 2025-05-30 07:00:19 UTC |
我们的扫描器未检测到威胁
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
028e398f1e1044351c122f1ab2159fa4
|
|
SHA1 |
bfa570cc7be1c2a7a5d2dfb98bbd4fc1d47b3ed2
|
|
SHA256 |
6e1ae5bcf7c933f20b32e682d858c36c48ed6ce0fd82a20c4369110c0a1a2f2a
|
|
SHA512 |
d985b4c9dbfdd2391621e1c316fe2ef6f62dc31af7cd12ff30936de8db3a3acd5f4122078230a7f899278eb4f65988a5b5a89df1fd77f09d5b3ced854c71f02c
|
|
ImpHash |
8507116e3d0e7e02e36e7dc5b8aa1af8
|
图标 |
哈希: a0ef7c81eee20e999575764306184ccf
模糊: 8341e53a6f1047f3c936b4d36dc8f542 dHash: 5050d274ccec82ae |
映像基址 | 0x00400000 |
入口点 | 0x006c6668 |
编译时间 | 2023-02-15 14:54:17 |
校验和 | 0x037ab559 (实际: 0x00362d05) |
操作系统版本 | 6.1 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
数字签名 | The expected hash does not match the digest in SpcInfo |
导入 | 14 库 |
导出 | 3 函数 |
资源 | 83 资源 |
节 | 10 节 |
FileDescription | Setup/Uninstall |
FileVersion | 51.1052.0.0 |
Comments | This installation was built with Inno Setup. |
CompanyName | Jahastech |
LegalCopyright | |
OriginalFileName | |
ProductName | NxFilter |
ProductVersion | 4.7.1.6 |
Translation | 0x0000 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
2,891,976 bytes | 2,892,288 bytes | 6.41 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
6D862601A48864DD93D15E7D2C714FE0 |
.itext |
0x002c4000 |
10,392 bytes | 10,752 bytes | 6.10 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
14817D9596460398CE8A10EC41885658 |
.data |
0x002c7000 |
37,464 bytes | 37,888 bytes | 6.22 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
B6C68A9CC08D787F829BEBE13BEEEBCE |
.bss |
0x002d1000 |
30,988 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x002d9000 |
14,778 bytes | 14,848 bytes | 5.29 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
1C7FAC207B7708F2D38F3ECED48727DC |
.didata |
0x002dd000 |
3,038 bytes | 3,072 bytes | 4.39 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
022CBD8E7EBBFB3DF44DFD43F92FA718 |
.edata |
0x002de000 |
151 bytes | 512 bytes | 1.85 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
29372B5D9FA8B5B431A37756AEE4C5B7 |
.tls |
0x002df000 |
76 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rdata |
0x002e0000 |
93 bytes | 512 bytes | 1.35 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
0E147EB88402EB8A56F168B457309291 |
.rsrc |
0x002e1000 |
505,344 bytes | 505,344 bytes | 6.43 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
DC918D3803BF90764109DCD47914448A |
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_CURSOR | 7 | 2,156 字节 | |
RT_ICON | 27 | 182,101 字节 | |
RT_STRING | 24 | 18,680 字节 | |
RT_RCDATA | 10 | 27,140 字节 | |
RT_GROUP_CURSOR | 7 | 140 字节 | |
RT_GROUP_ICON | 6 | 414 字节 | |
RT_VERSION | 1 | 1,300 字节 | |
RT_MANIFEST | 1 | 1,960 字节 |
产品 | NxFilter |
描述 | Setup/Uninstall |
文件版本 | 51.1052.0.0 |
签名日期 | 08:17 PM 02/02/2025 (124 天前) |
验证状态 | The digital signature of the object did not verify. |
签名者 | John Paul Chacha; Sectigo Public Code Signing CA R36; Sectigo Public Code Signing Root R46; Sectigo (AAA) |
副签名者 | Sectigo Public Time Stamping Signer R35; Sectigo Public Time Stamping CA R36; Sectigo Public Time Stamping Root R46 |
48 FC 93 B4 60 55 94 8D 36 A7 C9 8A 89 D6 94 16
7A 23 AE DA 53 69 96 0F 91 C8 3E 5C F4 C7 E3 3F
62 1D 6D 0C 52 01 9E 3B 90 79 15 20 89 21 1C 0A
3A 52 6A 2C 84 CE 55 E6 1D 65 FC CC 12 D8 E9 89
A2 A9 08 26 6D 26 BE 22 4F D6 21 19 FD 95 AE 3C
36 C2 B0 BD 7C 1B 3A E7 A3 B3 DD 36 CB C9 75 68
✓ 此文件已进行数字签名,证书链已验证。
The expected hash does not match the digest in SpcInfo
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要