| 文件名 | setup.exe |
| 文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
| 扫描器版本 | 1.0.215.174 |
| 数据库版本 | 2025-04-26 16:00:20 UTC |
我们的扫描器未检测到威胁
| 哈希类型 | 值 | 操作 |
|---|---|---|
| MD5 |
73b737337daf8096e9140ff38229fa41
|
|
| SHA1 |
499d64e040f1b1aa5f45115d3c04bee7520a4c7d
|
|
| SHA256 |
b9196933174086c41ce6e8d61131e55e3b50ed6b73f2f5d7b1fd456ba015f8ab
|
|
| SHA512 |
f8423b03e5fc04a648564e3bc89106ae1b1dc48edfb7032e7e629580e7a3f99e91ddf952e9ea3ec757e5ed5910fcdf290a1872b095726418245487d401f7d3b1
|
|
| ImpHash |
688f19b448660a5d7ed68eba2bda8b2f
|
| 图标 |
哈希: 28fd4b28ee26df641ce665653b1b314f
模糊: e66a836dbca05852a3ac53a78fd4b221 dHash: f0968ee8aae8e8b2 |
| 映像基址 | 0x00400000 |
| 入口点 | 0x004048d1 |
| 编译时间 | 2024-10-09 16:54:45 |
| 校验和 | 0x0003d895 (实际: 0x0003d895) |
| 操作系统版本 | 6.0 |
| PEiD 签名 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
| PDB 路径 | D:\NNRus.git\CPPDownloader.SCB\Setup\Release\JDWrapper.pdb |
| 数字签名 | Chain verification from CN=Poke Break, L=Paynesville, C=US (serial:8244338013359473444125470824395871871, sha1:bd8a6f785805e4dbd36b3d3cbf755d96e129a387) failed: Unable to build a validation path for the certificate "Common Name: Poke Break, Locality: Paynesville, Country: US" - no issuer matching "Common Name: Horseback Post, Locality: Biwabik, Country: US" was found |
| 导入 |
4 库
KERNEL32, WININET, USER32, ADVAPI32 |
| 导出 | 0 函数 |
| 资源 | 25 资源 |
| 节 | 7 节 |
| 名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
|---|---|---|---|---|---|---|
.text |
0x00001000 |
88,382 bytes | 88,576 bytes | 6.63 (压缩) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
B27A46CF8B7FFBEDB951CB695A915904 |
.rdata |
0x00017000 |
30,588 bytes | 30,720 bytes | 5.25 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
C9EC6A39DB36EA64133FA5B993700003 |
.data |
0x0001f000 |
5,776 bytes | 2,560 bytes | 2.35 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
43F0B29324758562BFAE2A66A66176B9 |
.gfids |
0x00021000 |
292 bytes | 512 bytes | 2.10 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
FF0471B4FEB27823ED77F9D7D7332150 |
.tls |
0x00022000 |
9 bytes | 512 bytes | 0.02 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
1F354D76203061BFDD5A53DAE48D5435 |
.rsrc |
0x00023000 |
94,704 bytes | 94,720 bytes | 4.03 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
6625F677F20F49549AC87BBEF90A0751 |
.reloc |
0x0003b000 |
4,908 bytes | 5,120 bytes | 6.47 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
95381F4BF4B1BFF2EE99DA3D205C3C37 |
1 检测到较高熵(≥6.5)的节 - 可能存在压缩
| 资源类型 | 数量 | 总大小 | 百分比 |
|---|---|---|---|
| RT_ICON | 18 | 92,154 字节 | |
| RT_MENU | 1 | 74 字节 | |
| RT_DIALOG | 1 | 312 字节 | |
| RT_STRING | 1 | 68 字节 | |
| RT_ACCELERATOR | 1 | 16 字节 | |
| RT_GROUP_ICON | 2 | 264 字节 | |
| RT_MANIFEST | 1 | 381 字节 |
| 验证状态 | A certificate chain could not be built to a trusted root authority. |
7A 6F 16 A7 0A EB 68 A9 4E AD 8D 4D 2E 6D 5D BE06 33 CD 3F 2B B0 E6 87 4A BE 76 E0 83 DA 96 7F✓ 此文件已进行数字签名,证书链已验证。
Chain verification from CN=Poke Break, L=Paynesville, C=US (serial:8244338013359473444125470824395871871, sha1:bd8a6f785805e4dbd36b3d3cbf755d96e129a387) failed: Unable to build a validation path for the certificate "Common Name: Poke Break, Locality: Paynesville, Country: US" - no issuer matching "Common Name: Horseback Post, Locality: Biwabik, Country: US" was found
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要
保持无恶意软件:使用 Gridinsoft 反恶意软件 保护您的 PC
Gridinsoft 反恶意软件正是如此——提供强大、用户友好的解决方案,让您安心,并不断更新以应对最新威胁。由网络安全专家设计,它提供实时保护和轻松删除恶意软件。这不仅仅是检测威胁;它是通过不间断的安全来增强您的数字生活。试一试,体验无忧浏览的感觉!