文件名 | bfetoolwin8.exe |
文件类型 |
PE32+ executable (console) x86-64, for MS Windows
|
扫描器版本 | 1.0.220.174 |
数据库版本 | 2025-07-13 02:00:17 UTC |
我们的扫描器未检测到威胁
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
67ce116a2d80be42df6a842fef395ab1
|
|
SHA1 |
bb0da29ff1d5258586f458016c9efebbd8c3f6f7
|
|
SHA256 |
c8552d235dee52897b11149a706a6dd7abf78bcf0f1dffd0d7f4df072dcb3948
|
|
SHA512 |
c6c0467371fb2c9b86827e83c454be25ac4dedfb81560bd46a150f3993fd3d936c8e3ad92d0d1ec7b40e59fde52622972d05bad76ea77e208088d555946c1ea3
|
|
ImpHash |
6e242f71b6f167684d1e013bd7da82b8
|
映像基址 | 0x140000000 |
入口点 | 0x140008644 |
编译时间 | 2019-02-28 02:00:27 |
校验和 | 0x00019e36 (实际: 0x00019e36) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32+ executable (console) x86-64, for MS Windows
|
PDB 路径 | X:\bt\1002112\repo\out\retail-amd64\BfeToolWin8\BfeToolWin8.pdb |
数字签名 | OK |
导入 |
9 库
KERNEL32, msvcrt, ntdll, ADVAPI32, WS2_32, RPCRT4, XmlLite, SHLWAPI, fwpuclnt |
导出 | 0 函数 |
资源 | 2 资源 |
节 | 6 节 |
CompanyName | Microsoft Corporation |
FileDescription | Compute-IaaS-VMAgent master (f60a828) Microsoft Azure® |
InternalName | BfeToolWin8 |
LegalCopyright | Copyright © Microsoft Corporation. All rights reserved. |
LegalTrademarks | Microsoft® is a registered trademark of Microsoft Corporation. |
OriginalFilename | BfeToolWin8.exe |
ProductName | Microsoft® CoReXT |
FileVersion | 2.7.41491.911 |
ProductVersion | 2.7.41491.911 |
PrivateBuild | (by azbldrun on SATAZHYP81-VM1) |
Translation | 0x0409 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
32,549 bytes | 32,768 bytes | 6.16 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
CE23635DFFFFFCD45A9E1F515BA61670 |
.rdata |
0x00009000 |
22,228 bytes | 22,528 bytes | 4.11 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
2A2149BF3735CD0F4462D7E56BCC80E7 |
.data |
0x0000f000 |
2,368 bytes | 1,024 bytes | 1.23 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
A214F7B338D1061252B9E10480139BA7 |
.pdata |
0x00010000 |
2,328 bytes | 2,560 bytes | 4.27 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
BEF50158D69B98766695CCD228AE178B |
.rsrc |
0x00011000 |
1,736 bytes | 2,048 bytes | 3.67 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
80344D9432EDD1E5CF088BD2B0A22083 |
.reloc |
0x00012000 |
124 bytes | 512 bytes | 1.57 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
CD24AECE1E677BF4CF3555881D981982 |
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
RT_VERSION | 1 | 1,188 字节 | |
RT_MANIFEST | 1 | 381 字节 |
产品 | Microsoft® CoReXT |
描述 | Compute-IaaS-VMAgent master (f60a828) Microsoft Azure® |
文件版本 | 2.7.41491.911 |
原始名称 | BfeToolWin8.exe |
签名日期 | 02:00 AM 02/28/2019 (2330 天前) |
验证状态 | Signed |
签名者 | Microsoft Corporation; Microsoft Code Signing PCA; Microsoft Root Certificate Authority |
副签名者 | Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA; Microsoft Root Certificate Authority |
内部名称 | BfeToolWin8 |
版权 | Copyright © Microsoft Corporation. All rights reserved. |
33 00 00 01 1C DB 6E 99 B7 B6 73 FA 6F 00 00 00 00 01 1C
33 00 00 01 B1 DD ED BA 54 E9 65 B8 5F 00 01 00 00 01 B1
61 33 26 1A 00 00 00 00 00 31
61 16 68 34 00 00 00 00 00 1C
33 00 00 01 03 5E 25 1C 99 1F A3 1E B8 00 00 00 00 01 03
61 0E 90 D2 00 00 00 00 00 03
33 00 00 00 F1 74 C5 D1 AE E3 3D 9B 3D 00 00 00 00 00 F1
61 09 81 2A 00 00 00 00 00 02
✓ 此文件已进行数字签名,证书链已验证。
OK
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要