文件名 | HiBitStartupManager-Portable.exe |
文件类型 |
Win32 EXE
|
魔术字节 | PE32 executable (GUI) Intel 80386, for MS Windows |
SSDEEP 哈希 |
98304:IFFI0EOKGZo0y9kJBjs+J4mQUSclu+Hdeq162pb4JwP8m12SoMt7tQtrUtftntkt:IA0EnkJvKdUS+HBlZcSoM9adUFFC
|
扫描器版本 | 1.0.165.174 |
数据库版本 | 2024-02-19 13:00:23 UTC |
被 3 个安全引擎检测到 - 需要谨慎
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
c4d5c486e5ca20a34674b125aa3014f1
|
|
SHA1 |
a9010956f0fcad1fb559070cf6baed1929a8ccef
|
|
SHA256 |
dec07d5afcafcbf9d6735672f6b65b16e7c4acfc92ada4b8d29690e472e3fef8
|
|
SHA512 |
fcd73c7848ac097177e3f8bb4b875f2c0c3e1e508c18389df212bb9c30b7312ad20043709678161d39fcf527341706cdcb619bcfbcb1b0564edba0a13a503d0e
|
|
ImpHash |
b8abb7d97c8f4a4617c9c6bf9923b370
|
图标 |
哈希: 012ebb3744df70e90805cbdb4810c10a
模糊: d12129e7330c6ccce06efdec71df2961 dHash: b233794d4d7973be |
映像基址 | 0x00400000 |
入口点 | 0x009e3f1c |
编译时间 | 2024-02-18 18:09:50 |
校验和 | 0x00000000 (实际: 0x009295c4) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
数字签名 | The PE file does not contain a certificate table. |
导入 | 16 库 |
导出 | 2 函数 |
资源 | 167 资源 |
节 | 11 节 |
CompanyName | HiBitSoftware |
FileVersion | 2.6.35.0 |
InternalName | HiBit Startup Manager |
LegalCopyright | Copyright © 2017-2024 HiBitSoftware |
LegalTrademarks | HiBitSoftware |
OriginalFilename | HiBitStartupManager |
ProductVersion | 2.6.35.0 |
Comments | https://www.hibitsoft.ir |
ProgramID | com.embarcadero.StartupManager |
FileDescription | HiBit Startup Manager |
ProductName | HiBit Startup Manager |
Translation | 0x0409 0x04e4 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
6,154,288 bytes | 6,154,752 bytes | 6.31 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
BC06D959DDBD216E96DDD8AEBEC9715D |
.itext |
0x005e0000 |
17,796 bytes | 17,920 bytes | 6.16 (正常) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
E547484E546039E0CB7EBCFE573D2920 |
.data |
0x005e5000 |
182,680 bytes | 182,784 bytes | 5.88 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
853B0368463055551B22DF9B909C48DB |
.bss |
0x00612000 |
112,944 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x0062e000 |
17,774 bytes | 17,920 bytes | 5.26 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
DED064B9C508FDD64AEDC429879F2891 |
.didata |
0x00633000 |
26,898 bytes | 27,136 bytes | 5.03 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
A12F2EE847B1576D0548F7EFEA1C9455 |
.edata |
0x0063a000 |
119 bytes | 512 bytes | 1.41 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
C5067137686F5005942D69E2BC0605B3 |
.tls |
0x0063b000 |
84 bytes | 0 bytes | 0.00 (正常) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rdata |
0x0063c000 |
93 bytes | 512 bytes | 1.40 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
D7F27AC8103AEB1D3A0B8AB4F0EAC2F1 |
.reloc |
0x0063d000 |
483,780 bytes | 483,840 bytes | 6.71 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
D3C9B59745F161054E68FE2E89140E0A |
.rsrc |
0x006b4000 |
2,658,816 bytes | 2,658,816 bytes | 7.09 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
C41B214145F862B538161B2A89B0EAD2 |
2 检测到较高熵(≥6.5)的节 - 可能存在压缩
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
VCLSTYLE | 7 | 801,716 字节 | |
RT_CURSOR | 9 | 2,772 字节 | |
RT_BITMAP | 12 | 12,536 字节 | |
RT_ICON | 7 | 60,712 字节 | |
RT_STRING | 47 | 53,684 字节 | |
RT_RCDATA | 73 | 1,712,860 字节 | |
RT_GROUP_CURSOR | 9 | 180 字节 | |
RT_GROUP_ICON | 1 | 104 字节 | |
RT_VERSION | 1 | 1,048 字节 | |
RT_MANIFEST | 1 | 1,506 字节 |
产品 | HiBit Startup Manager |
描述 | HiBit Startup Manager |
文件版本 | 2.6.35.0 |
原始名称 | HiBitStartupManager |
内部名称 | HiBit Startup Manager |
版权 | Copyright © 2017-2024 HiBitSoftware |
✓ 此文件已进行数字签名,证书链已验证。
The PE file does not contain a certificate table.
建议: 验证文件来源并确保它来自可信的发布者.
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要