Gridinsoft Logo

Steam_-api.dll Trojan Heuristic Analysis

Technical Analysis

File Name steam_-api.dll
File Type
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.216.174
Database Version 2025-05-18 14:00:25 UTC

Trojan.Heur!.032100A0

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
570,880
File Size (bytes)
2025-05-18
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
ff15612cd83a8e752b976d45519d360f
SHA1
0bbaba59f15d99f96d69d024dc53445ce56cf2c5
SHA256
2f00745eda6f2d173789c0b948714c5318d676e2eb7b42bed99de71e0edf397e
SHA512
fea624e13d848f544aeb9532d7f1069b1c6a74d824f8b3048c5b9546f1b75649e7aca6e5b08ddebf7e8168f78f2d0e531baf30c5341fe909dcceac2016af8441
ImpHash
12b754670ab03329a68f8c990b5150dc

PE Analysis

Basic Information

Image Base 0x10000000
Entry Point 0x10b4871e
Compilation Time 2013-08-14 05:55:14
Checksum 0x00099b69 (Actual: 0x00099b69)
OS Version 5.1
PEiD Signatures PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 6 libraries
KERNEL32, USER32, ADVAPI32, WS2_32, WINHTTP, PSAPI
Exports 63 functions
Resources 2 Resources
Sections 7 Sections

Version Information

CompanyName Valve Corporation
FileDescription Steam Client API (buildbot_winslave04_steam_steam_rel_client_win32@winslave04)
FileVersion 1.83.31.47
InternalName Steam Client API
LegalCopyright Copyright (C) 1996-2013 Valve Corporation
OriginalFilename Steam_API.dll
ProductName Steam Client API
ProductVersion 1.83.31.47
Translation 0x0804 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 191,828 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.rdata 0x00030000 81,531 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.data 0x00044000 10,521,092 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.THEGFW0 0x00a4d000 482,804 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.THEGFW1 0x00ac3000 567,576 bytes 567,808 bytes 7.97 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D970E18EB13A63423F51D8B81D03FB08
.reloc 0x00b4e000 176 bytes 512 bytes 1.83 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ DE13F1B65FB0CB5043991ACE122CC762
.rsrc 0x00b4f000 1,434 bytes 1,536 bytes 3.97 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 861804B15CFDE7B3207340A1F779111D
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 2 (1,274 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 928 bytes
72.8%
RT_MANIFEST 1 346 bytes
27.2%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.032100A0 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.032100A0 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware