| File Name | ridoc.exe |
| File Type |
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
| Scanner Version | 1.0.228.174 |
| Database Version | 2025-10-20 23:00:13 UTC |
No threats detected by our scanner
| Hash Type | Value | Action |
|---|---|---|
| MD5 |
1d0680ba6c55fafe1f5a34f329c08a01
|
|
| SHA1 |
ef1dd148495df1d942b9e753b7e731c6f9ea5f63
|
|
| SHA256 |
9afd5a1a545ebb233aab8be389aa596bff5dc77c9460f45e9a8ae4f9346fdfac
|
|
| SHA512 |
2661ffec34f919ec921971f0b571c425f8c8de45c28c3f2a38c1e8086bd06c379fa98926bf8dfb9a04ad155480b2e7c1a284c1be16d511c9e135c1c655bcbe0d
|
|
| ImpHash |
6e7f9a29f2c85394521a08b9f31f6275
|
| Icon |
Hash: fe46efaa297ea7febe12bfc24a27b426
Fuzzy: e00aefef4cfc38c4446120621c7e74df dHash: 7ceeccdcdcecc8f0 |
| Image Base | 0x00400000 |
| Entry Point | 0x004034c5 |
| Compilation Time | 2021-07-24 22:21:04 |
| Checksum | 0x020531d9 (Actual: 0x020531d9) |
| OS Version | 4.0 |
| PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
|
| Digital Signature | OK |
| Imports |
7 libraries
ADVAPI32, SHELL32, ole32, COMCTL32, USER32, GDI32, KERNEL32 |
| Exports | 0 functions |
| Resources | 26 Resources |
| Sections | 5 Sections |
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
|---|---|---|---|---|---|---|
.text |
0x00001000 |
26,515 bytes | 26,624 bytes | 6.50 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
C25464D6F87775EF687D2492F92DDF9A |
.rdata |
0x00008000 |
5,284 bytes | 5,632 bytes | 5.01 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
E36C6AD0568CD039E0C7810069438D6D |
.data |
0x0000a000 |
176,152 bytes | 1,536 bytes | 4.16 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
33B1D611A00420C98FA82231FEAA907B |
.ndata |
0x00036000 |
77,824 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rsrc |
0x00049000 |
25,696 bytes | 26,112 bytes | 4.30 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
A2BAC53318561A671AAB850BFEF7E41D |
1 section(s) with elevated entropy (≥6.5) - possible compression
| Resource Type | Count | Total Size | Percentage |
|---|---|---|---|
| RT_ICON | 4 | 17,472 bytes | |
| RT_DIALOG | 20 | 5,672 bytes | |
| RT_GROUP_ICON | 1 | 62 bytes | |
| RT_MANIFEST | 1 | 1,070 bytes |
| Signing Date | 06:53 PM 10/18/2025 (83 days ago) |
| Verification Status | Signed |
| Signers | OOO Kompaniya Riman; GlobalSign GCC R45 CodeSigning CA 2020; GlobalSign Code Signing Root R45; GlobalSign Root CA - R3 |
| Counter Signers | Globalsign TSA for CodeSign1 - R6; GlobalSign Timestamping CA - SHA384 - G4; GlobalSign Root CA - R6 |
78 03 18 42 45 70 8A 41 CF 6F 01 B8 EE B4 A9 5477 BD 0E 03 A1 B7 08 F8 54 AB 06 72 10 D9 04 4749 26 B2 D3 0E 62 66 6D 5C 0B 93 4C01 00 0B 20 05 B3 94 07 62 DB 3E 36 79 94 9B A901 EC 1C 92 40 DE FD 2E 40 5D 7C 47 7445 E6 BB 03 83 33 C3 85 65 48 E6 FF 45 51✓ This file has been digitally signed and the certificate chain has been verified
OK
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important
Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware
Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!