文件名 | setup.dll |
文件类型 |
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
扫描器版本 | 1.0.212.174 |
数据库版本 | 2025-04-08 18:01:03 UTC |
我们的扫描器未检测到威胁
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
da577ee2618cab94ab5f964d89b6e43a
|
|
SHA1 |
e5c163a996ce266c9b760efbefa9b6049689bff0
|
|
SHA256 |
992b5b38336a7d0869f1d02939eb82e26141f2bd7298caaa571953317ca5f3bf
|
|
SHA512 |
376969e227baed5070a9615e6556918dc681bc206978e5c4cba158a70dd64b93267682b2750cc71238d74eddee90adab8bea0ab2212d8e10e4bf7c2695211f78
|
|
ImpHash |
7d65b6c1a954da6bd093be0b9a78a6d9
|
图标 |
哈希: 5f94b95007880b3f19d43ffec7d49425
模糊: f3f5c220b4667001ff0764453ac23c10 dHash: e0c8cec6c6c6c8e0 |
映像基址 | 0x180000000 |
入口点 | 0x18000b2a8 |
编译时间 | 2015-07-30 12:35:56 |
校验和 | 0x000cc1f8 (实际: 0x000cc1f8) |
操作系统版本 | 6.1 |
PEiD 签名 |
PE32+ executable (DLL) (GUI) x86-64, for MS Windows
|
PDB 路径 | P:\Target\x64\ship\setupexe\x-none\setupbootstrapper.pdb per.pdb 0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 |
数字签名 | OK |
导入 |
5 库
ADVAPI32, KERNEL32, ole32, OLEAUT32, WINTRUST |
导出 | 1 函数 |
资源 | 26 资源 |
节 | 7 节 |
CompanyName | Microsoft Corporation |
FileDescription | Microsoft Setup Bootstrapper |
FileVersion | 16.0.4266.1001 |
InternalName | setup.exe |
LegalTrademarks1 | Microsoft® is a registered trademark of Microsoft Corporation. |
LegalTrademarks2 | Windows® is a registered trademark of Microsoft Corporation. |
OriginalFilename | setup.exe |
ProductName | Microsoft Setup Bootstrapper |
ProductVersion | 16.0.4266.1001 |
MOSEVersion | BETA |
Translation | 0x0000 0x04e4 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
313,552 bytes | 313,856 bytes | 6.37 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
EB36BF974EBDA1405809AC0EA9AE2DDA |
.rdata |
0x0004e000 |
226,804 bytes | 226,816 bytes | 4.41 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
6E799EC45CE58E18514F873FE52DF6E7 |
.data |
0x00086000 |
32,624 bytes | 32,768 bytes | 2.43 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
5D5EE3877D5C99A404C2C1BEF6E966F5 |
.pdata |
0x0008e000 |
22,848 bytes | 23,040 bytes | 5.63 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A669B7E293E9F18FFE265576CE71CF53 |
.tls |
0x00094000 |
2 bytes | 512 bytes | 0.00 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
BF619EAC0CDF3F68D496EA9344137E8B |
.rsrc |
0x00095000 |
168,024 bytes | 168,448 bytes | 2.06 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
FD42A7B16F6D34D4F50A27524015DB32 |
.reloc |
0x000bf000 |
5,708 bytes | 6,144 bytes | 5.33 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
0BCB72F86F01208467F2B0B1AD6D9104 |
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_ICON | 23 | 163,678 字节 | |
RT_GROUP_ICON | 1 | 328 字节 | |
RT_VERSION | 1 | 1,108 字节 | |
RT_MANIFEST | 1 | 1,509 字节 |
产品 | Microsoft Setup Bootstrapper |
描述 | Microsoft Setup Bootstrapper |
文件版本 | 16.0.4266.1001 |
原始名称 | setup.exe |
签名日期 | 02:03 PM 07/31/2015 (3599 天前) |
验证状态 | Signed |
签名者 | Microsoft Corporation; Microsoft Code Signing PCA; Microsoft Root Certificate Authority |
副签名者 | Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA; Microsoft Root Certificate Authority |
内部名称 | setup.exe |
33 00 00 00 71 B3 2E 8A 6B 82 AA 1F 4E 00 00 00 00 00 71
33 00 00 01 0A 2C 79 AE D7 79 7B A6 AC 00 01 00 00 01 0A
61 33 26 1A 00 00 00 00 00 31
61 16 68 34 00 00 00 00 00 1C
✓ 此文件已进行数字签名,证书链已验证。
OK
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要