| File Name | processhacker-2.39-setup.exe |
| File Type |
Win32 EXE
|
| Magic Bytes | PE32 executable (GUI) Intel 80386, for MS Windows |
| SSDEEP Hash |
49152:l9hfV/U5NkLXXzGZjt6kFTCVP6hWE0wvmk/eE+FrAl+NGsOSE6IX8pq:Dh9/ULkjKxtTGP6VZd2rAcvOSE6Nq
|
| Scanner Version | 1.0.232.174 |
| Database Version | 2026-01-08 09:00:28 UTC |
Detected by 32 security engines - requires caution
| Hash Type | Value | Action |
|---|---|---|
| MD5 |
54daad58cce5003bee58b28a4f465f49
|
|
| SHA1 |
162b08b0b11827cc024e6b2eed5887ec86339baa
|
|
| SHA256 |
28042dd4a92a0033b8f1d419b9e989c5b8e32d1d2d881f5c8251d58ce35b9063
|
|
| SHA512 |
8330de722c8800ff64c6b9ea16a4ff7416915cd883e128650c47e5cb446dd3aaa2a9ba5c4ecda781d243be7fb437b054bbcf942ea714479e6cc3cef932390829
|
|
| ImpHash |
884310b1928934402ea6fec1dbd3cf5e
|
| Icon |
Hash: 269727acacba789cd7a93601617416ed
Fuzzy: c2b74ba8bb134400487ce1be7b5c9c96 dHash: f8a48686aeb6f3e0 |
| Image Base | 0x00400000 |
| Entry Point | 0x0040a5f8 |
| Compilation Time | 1992-06-19 22:22:17 |
| Checksum | 0x0022e77b (Actual: 0x0022e77b) |
| OS Version | 1.0 |
| PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
| Digital Signature | OK |
| Imports |
5 libraries
kernel32, user32, oleaut32, advapi32, comctl32 |
| Exports | 0 functions |
| Resources | 23 Resources |
| Sections | 8 Sections |
| Comments | This installation was built with Inno Setup. |
| CompanyName | wj32 |
| FileDescription | Process Hacker Setup |
| FileVersion | 2.39 (r124) |
| LegalCopyright | Copyright © 2010-2016, Process Hacker Team. Licensed under the GNU GPL, v3. |
| ProductName | Process Hacker |
| ProductVersion | 2.39 (r124) |
| Translation | 0x0000 0x04b0 |
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
|---|---|---|---|---|---|---|
CODE |
0x00001000 |
40,240 bytes | 40,448 bytes | 6.63 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
611A4D7A24DD9B18A256468A5D7453F5 |
DATA |
0x0000b000 |
592 bytes | 1,024 bytes | 2.75 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
2F7F9F859C8B4B133ABF78CEBD99CC90 |
BSS |
0x0000c000 |
3,728 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x0000d000 |
2,384 bytes | 2,560 bytes | 4.43 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
BB5485BF968B970E5EA81292AF2ACDBA |
.tls |
0x0000e000 |
8 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rdata |
0x0000f000 |
24 bytes | 512 bytes | 0.20 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ
|
9BA824905BF9C7922B6FC87A38B74366 |
.reloc |
0x00010000 |
2,244 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ
|
D41D8CD98F00B204E9800998ECF8427E |
.rsrc |
0x00011000 |
104,316 bytes | 104,448 bytes | 7.30 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ
|
98F54B0DE9ADC0A4FF04354819FCF891 |
2 section(s) with elevated entropy (≥6.5) - possible compression
| Resource Type | Count | Total Size | Percentage |
|---|---|---|---|
| RT_ICON | 13 | 97,235 bytes | |
| RT_STRING | 6 | 2,710 bytes | |
| RT_RCDATA | 1 | 44 bytes | |
| RT_GROUP_ICON | 1 | 188 bytes | |
| RT_VERSION | 1 | 1,268 bytes | |
| RT_MANIFEST | 1 | 1,580 bytes |
| Product | Process Hacker |
| Description | Process Hacker Setup |
| File Version | 2.39 (r124) |
| Signing Date | 01:35 AM 03/29/2016 (3574 days ago) |
| Verification Status | Signed |
| Signers | Wen Jia Liu; DigiCert High Assurance Code Signing CA-1; DigiCert |
| Counter Signers | DigiCert Timestamp Responder; DigiCert Assured ID CA-1; DigiCert |
| Copyright | Copyright © 2010-2016, Process Hacker Team. Licensed under the GNU GPL, v3. |
0F F1 EF 66 BD 62 1C 65 B7 4B 4D E4 14 25 71 7F03 01 9A 02 3A FF 58 B1 6B D6 D5 EA E6 17 F0 6602 C4 D1 E5 8A 4A 68 0C 56 8D A3 04 7E 7E 4D 5F06 FD F9 03 96 03 AD EA 00 0A EB 3F 27 BB BA 1B04 0C B4 1E 4F B3 70 C4 5C 43 44 76 51 62 58 2F0B 7E 10 90 3C 38 49 0F FA 2F 67 9A 87 A1 A7 B902 CE 42 94 59 02 A4 F3 C0 40 B0 FF 77 93 D1 4F0A A1 25 D6 D6 32 1B 7E 41 E4 05 DA 36 97 C2 15✓ This file has been digitally signed and the certificate chain has been verified
OK
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important
Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware
Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!