在线病毒检测器 | v.1.0.194.174 |
数据库版本: | 2024-10-27 14:00:27 |
File | nbveek.exe |
已检查 | 2024-10-27 12:23:23 |
MD5 | bc45f9797f848df442a883f994adad4a |
SHA1 | 192cc4bc45c4f47147631d04a7fafe418acf7131 |
SHA256 | bef6710dbe58cb2a400e94e471509b8bb3605ef74ba6c177f9744254ab2278e3 |
SHA512 | c4d4e2f53eaf779e889e86cc059c3b7a8518bb8c86e58dd0bd25d4b4683bca59ce36afd6e5b1cbf62e93437d08beda2c74aae74abf1af623678b636c83461031 |
Imphash | dd0e4efabc62274a7cfb37b4b7a2951d |
File Size | 240640 bytes |
Gridinsoft能够识别并消除Trojan.Amadey.65344.dd!yf,无需进一步的用户干预。
Image Base: | 0x00400000 |
Entry Point: | 0x004175b6 |
Compilation: | 2023-01-04 21:36:22 |
Checksum: | 0x00000000 (Actual: 0x0004a012) |
OS Version: | 6.0 |
PDB Path: | D:\Mktmp\Amadey\Release\Amadey.pdb |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows |
Sign: | No valid SignedData structure was found. |
Sections: | 5 |
Imports: | KERNEL32, ADVAPI32, SHELL32, WININET, |
Exports: | 0 |
Resources: | 1 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | MD5 | 熵 |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0002c9dd | 0x0002ca00 | 33ff47287110ce682075e608ea195cea | 6.45 |
.rdata | 0x0002e000 | 0x000098e0 | 0x00009a00 | 7bf90cd7ada8c0f40e8232a392fcccb1 | 4.96 |
.data | 0x00038000 | 0x00004480 | 0x00001800 | 265878b6bed60a154cc33e2bbc5ef3c7 | 1.40 |
.rsrc | 0x0003d000 | 0x000001e0 | 0x00000200 | bde1b22770db5de52439d7b03653475d | 4.72 |
.reloc | 0x0003e000 | 0x00002870 | 0x00002a00 | 4cec25ef93e74114eb9294386b36ed7d | 6.54 |