Verificador de Vírus Online | v.1.0.195.174 |
Versão do Banco de Dados: | 2024-11-01 02:00:19 |
O "Heur" significa "heurística", o que significa que usamos um conjunto de regras, algoritmos ou análises comportamentais para detectar ameaças potenciais que podem não ter uma assinatura específica conhecida. É uma abordagem proativa para identificar comportamentos suspeitos ou padrões de código que podem indicar a presença de um cavalo de Troia ou outro malware. O comportamento ou as características do arquivo acionaram a análise heurística como potencialmente maliciosos. No entanto, isso não confirma necessariamente que o arquivo seja realmente um cavalo de Troia. Pode ser um falso positivo, em que um programa legítimo exibe um comportamento que se assemelha a atividade maliciosa.
File | libmwlmgrimpl.dll |
Verificado | 2024-11-01 00:31:43 |
MD5 | 8461aab351d644b1c80c663085f86fe5 |
SHA1 | 7b9fbdb92354b1d2ab966e7009ef4d9b52eadf1a |
SHA256 | decd5ad8ab250463c63738f60358ae803f65af3b7def4c2a2820c2313904ffbd |
SHA512 | d4dd8617b7f5718884527dcfcab428ebcc899cc0430f501be0887bb9414660c83aa2e91fe32aa549751af8d02cebef6882ae93faa72c7b3a6222dc260226ab33 |
Imphash | b4dc092c279246678d978fd312d50b88 |
File Size | 3914600 bytes |
Gridinsoft tem a capacidade de identificar e eliminar Trojan.Heur!.00216032 sem a necessidade de intervenção adicional do usuário.
Image Base: | 0x180000000 |
Entry Point: | 0x1801c3df4 |
Compilation: | 2010-12-19 23:49:35 |
Checksum: | 0x003c261e (Actual: 0x003be49c) |
OS Version: | 6.0 |
PDB Path: | B:\matlab\bin\win64\matlab_startup_plugins\lmgrimpl\libmwlmgrimpl.pdb |
PEiD: | PE32+ executable (DLL) (console) x86-64, for MS Windows |
Sign: | The expected hash does not match the digest in SpcInfo |
Sections: | 14 |
Imports: | libmwflhttpclient_core, ddux, ddux_loggingapi, libmwagentspfframeworksetup, libmwcppmicroservices, libmwi18n, libmwfoundation_filesystem, libmwfl, libmwflstoragevfs, libmwflurlmanager, libmwflurlmgrfactory, libmwfoundation_paths, libmwfoundation_usm, libmwlicensemarkerfile, libmwlogin, libmwms, libmwollauthzsharedutils, libmwrelease_info, libmwollsharedexceptions, libmwproductdata, libmwsearch_path_events, libmwsearch_path_utilities, libmwserviceprocess, libmwservices, libut, mvm, mlutil, opcmodel, libmwfoundation_log, libmwcpp11compat, mwboost_log-vc143-mt-x64-1_78, mwboost_thread-vc143-mt-x64-1_78, CppMicroServices3, ADVAPI32, COMCTL32, COMDLG32, NETAPI32, WS2_32, SHLWAPI, dhcpcsvc, USERENV, RPCRT4, msi, CRYPT32, WININET, IPHLPAPI, ole32, tbb, xerces-c_3_2, KERNEL32, USER32, SHELL32, OLEAUT32, MSVCP140, bcrypt, VCRUNTIME140, VCRUNTIME140_1, api-ms-win-crt-runtime-l1-1-0, api-ms-win-crt-heap-l1-1-0, api-ms-win-crt-time-l1-1-0, api-ms-win-crt-stdio-l1-1-0, api-ms-win-crt-string-l1-1-0, api-ms-win-crt-convert-l1-1-0, api-ms-win-crt-filesystem-l1-1-0, api-ms-win-crt-environment-l1-1-0, api-ms-win-crt-math-l1-1-0, api-ms-win-crt-locale-l1-1-0, api-ms-win-crt-utility-l1-1-0, |
Exports: | 20 |
Resources: | 1 |
Nome | Endereço Virtual | Tamanho Virtual | Tamanho Bruto | MD5 | Entropia |
---|---|---|---|---|---|
.text | 0x00001000 | 0x001e74a3 | 0x001e7600 | a48cae8c3380958b8bffcde94e584781 | 6.21 |
.textidx | 0x001e9000 | 0x000d3a53 | 0x000d3c00 | b49619e8f68328339b204324695751b5 | 6.19 |
jkl.text | 0x002bd000 | 0x00008b50 | 0x00008c00 | 8198010b82f7a40b2a0d8c3be0d29b05 | 6.21 |
jkl.bss | 0x002c6000 | 0x000000c8 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.rdata | 0x002c7000 | 0x000b22ce | 0x000b2400 | b285b7d8d6a68cea21f6b139cd3b02f5 | 5.92 |
.data | 0x0037a000 | 0x0001ae98 | 0x00013800 | 4ebe9ff46a33e9c0f845e8fc51ef6afd | 4.96 |
.pdata | 0x00395000 | 0x00029ae4 | 0x00029c00 | 25625eba851f85289231aa093fdfb5a7 | 6.25 |
jkl.data | 0x003bf000 | 0x00000018 | 0x00000200 | 4147f67d7fb20a3ccc4c8df94a549025 | 0.55 |
jkl.rdat | 0x003c0000 | 0x000003a0 | 0x00000400 | ae37d0635af473ed433c419f79074644 | 7.21 |
jkl.xdat | 0x003c1000 | 0x00000c44 | 0x00000e00 | f43095a44c8ef0a1226cf65516ed3468 | 4.41 |
jkl.pdat | 0x003c2000 | 0x00000804 | 0x00000a00 | 04b81b339a0097313c8f9cc7377037e1 | 3.30 |
.rsrc | 0x003c3000 | 0x000002a0 | 0x00000400 | b0b1dcc7d5ffe36d96f78efa065ca91c | 4.09 |
.reloc | 0x003c4000 | 0x00003154 | 0x00003200 | 9d23c24fbb3a974feec43dc2c9777321 | 5.45 |
.crdata | 0x003c8000 | 0x00000013 | 0x00000200 | 5ff54134bf75260b5ccdbb5ea0403cb5 | 2.64 |