在线病毒检测器 | v.1.0.165.174 |
数据库版本: | 2024-02-21 18:00:25 |
这是一个通用检测名称,用于识别具有特洛伊木马特征的潜在有害或可疑文件或程序。这是一种伪装成合法或良性程序但包含恶意代码或功能的恶意软件。
File | ep_setup.exe |
已检查 | 2024-02-21 16:35:43 |
MD5 | 7ea3f1aacb347b9acd4a536197330eaa |
SHA1 | beab07dde096910d7214d82dc12f383df1fa399c |
SHA256 | e44790e25db09d1fdcaa1b4a8e868a31d646a260c9df4923aea7be8efa0d8e1d |
SHA512 | cf1f53481b6b9f723e6832f027dd496ba1e9bad3bd797ab8626f0d84a17a0e115d717d3d0915954044867b5eabb20936cba1c44afe5ae23c8d75fc1dcc963493 |
Imphash | d49bd0b9e00ddd48d6db53cb9d0d703f |
File Size | 2362368 bytes |
Gridinsoft能够识别并消除Spy.Win64.Gen.tr,无需进一步的用户干预。
CompanyName | VALINET Solutions SRL |
FileDescription | ExplorerPatcher Setup Program |
FileVersion | 22621.2861.62.2 |
InternalName | ep_setup.exe |
LegalCopyright | Copyright (C) 2006-2023 VALINET Solutions SRL. All rights reserved. |
OriginalFilename | ep_setup.exe |
ProductName | ExplorerPatcher |
ProductVersion | 22621.2861.62.2 |
Translation | 0x0409 0x04b0 |
Image Base: | 0x140000000 |
Entry Point: | 0x140005574 |
Compilation: | 2023-12-22 13:29:42 |
Checksum: | 0x00000000 (Actual: 0x00248f6e) |
OS Version: | 6.0 |
PDB Path: | D:\a\ExplorerPatcher\ExplorerPatcher\build\Release\ep_setup.pdb |
PEiD: | PE32+ executable (GUI) x86-64, for MS Windows |
Sign: | The PE file does not contain a certificate table. |
Sections: | 7 |
Imports: | KERNEL32, USER32, ADVAPI32, SHELL32, ole32, OLEAUT32, RstrtMgr, VERSION, WININET, SHLWAPI, |
Exports: | 4 |
Resources: | 34 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | MD5 | 熵 |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0001d920 | 0x0001da00 | 220e1a968557f4e866ffb94d4302571b | 6.47 |
.rdata | 0x0001f000 | 0x0000dbd2 | 0x0000dc00 | 716a803b0b88a94e1037fe8c98e910e6 | 4.96 |
.data | 0x0002d000 | 0x00001f40 | 0x00000c00 | 4c8006cc3b6da7b6542bd538d9c2a783 | 1.94 |
.pdata | 0x0002f000 | 0x00001734 | 0x00001800 | 04eba29bbe7c56bc101a92293d1345b4 | 5.17 |
_RDATA | 0x00031000 | 0x000000fc | 0x00000200 | 7fd734216981807bb898c21c96eaf0aa | 1.98 |
.rsrc | 0x00032000 | 0x002123f8 | 0x00212400 | 08a61c4d5047b1c3e897fbcc5d9274d1 | 6.09 |
.reloc | 0x00245000 | 0x000006b4 | 0x00000800 | 3cfcb9b999fbb971d1f1cf25b5367cf3 | 5.03 |