文件名 | ResourceHacker.exe |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
扫描器版本 | 1.0.191.174 |
数据库版本 | 2024-10-06 11:00:39 UTC |
我们的扫描器未检测到威胁
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
d8440bc5507c119b5a7d90f9ca0a263e
|
|
SHA1 |
ba3bc06439cca1e9478f0279256e2181b5fb9ace
|
|
SHA256 |
92c37098909f035fa6fb4be4a014423a1520f082f07df0e68c2f880799576f15
|
|
SHA512 |
09a963739f5ceeb2c152bd9c0d7066d60f088336c616742db6fe1a8a43a428c7aa016c393b42cc9c1719223831d43c05ce053f3d7093cbf926d63edfb141ab69
|
|
ImpHash |
bb677fbadcdf2eca3595d1faeddecfdd
|
图标 |
哈希: fc73c884f5a9a89fe96532f193fb9f4c
模糊: 98e09c346f78dc619916c7558ac0f8f3 dHash: 222625ada6b5b112 |
映像基址 | 0x00400000 |
入口点 | 0x007846ec |
编译时间 | 2023-11-19 10:07:11 |
校验和 | 0x00000000 (实际: 0x005e7053) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
数字签名 | The PE file does not contain a certificate table. |
导入 | 15 库 |
导出 | 2 函数 |
资源 | 258 资源 |
节 | 11 节 |
CompanyName | Angus Johnson |
FileDescription | Resource viewer, decompiler & recompiler |
FileVersion | 5.2.7.427 |
InternalName | ResHack |
LegalCopyright | (c) Angus Johnson 1999-2019 |
OriginalFilename | ResHack |
ProductVersion | 5.0.0.0 |
ProgramID | com.embarcadero.ResourceHacker |
ProductName | ResourceHacker |
Translation | 0x0409 0x04e4 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
3,671,280 bytes | 3,671,552 bytes | 6.47 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
CA8AA0C66D299B64289A886C9D9E4855 |
.itext |
0x00382000 |
10,304 bytes | 10,752 bytes | 6.21 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
016BD33A5673F4DE7FACF989FD3E5B19 |
.data |
0x00385000 |
46,064 bytes | 46,080 bytes | 6.08 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
C4F84015E72800616163906223E174FF |
.bss |
0x00391000 |
232,604 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x003ca000 |
15,322 bytes | 15,360 bytes | 5.27 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
00AA6CE084A810F13BAE1C73705A692C |
.didata |
0x003ce000 |
3,308 bytes | 3,584 bytes | 4.20 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
1DA35772ACA708DFD165C6E6E8F70A7F |
.edata |
0x003cf000 |
119 bytes | 512 bytes | 1.42 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
35901220AC7A1BF3D47FD7D67AA0630E |
.tls |
0x003d0000 |
84 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rdata |
0x003d1000 |
93 bytes | 512 bytes | 1.35 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
8E2C0E8AD1414763FD2E00FCF9406CE9 |
.reloc |
0x003d2000 |
304,700 bytes | 305,152 bytes | 6.70 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
E5B0C65D64B77CA577B08FD22C34CD9F |
.rsrc |
0x0041d000 |
2,087,936 bytes | 2,087,936 bytes | 4.67 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
C0C09D0FAE674E890DC8E3FF5A92BEDB |
1 检测到较高熵(≥6.5)的节 - 可能存在压缩
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
TEMPLATES | 11 | 5,149 字节 | |
TEXT | 17 | 97,847 字节 | |
RT_CURSOR | 26 | 39,128 字节 | |
RT_BITMAP | 51 | 1,431,828 字节 | |
RT_ICON | 30 | 223,142 字节 | |
RT_DIALOG | 2 | 164 字节 | |
RT_STRING | 46 | 44,612 字节 | |
RT_RCDATA | 44 | 226,554 字节 | |
RT_GROUP_CURSOR | 20 | 456 字节 | |
RT_GROUP_ICON | 9 | 474 字节 | |
RT_VERSION | 1 | 860 字节 | |
RT_MANIFEST | 1 | 1,801 字节 |
产品 | ResourceHacker |
描述 | Resource viewer, decompiler & recompiler |
文件版本 | 5.2.7.427 |
原始名称 | ResHack |
内部名称 | ResHack |
版权 | (c) Angus Johnson 1999-2019 |
✓ 此文件已进行数字签名,证书链已验证。
The PE file does not contain a certificate table.
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要