Loader.exe Trojan Heuristic Analysis

Trojan Heuristic
Updated on 2024-04-20 (4 months ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.172.174
DB Version:2024-04-20 17:00:32

Trojan.Heur!.02212023

The "Heur" stands for "heuristic," which means we use a set of rules, algorithms, or behavioral analysis to detect potential threats that may not have a specific, known signature. It's a proactive approach to identifying suspicious behavior or code patterns that could indicate the presence of a Trojan or other malware. The file's behavior or characteristics triggered the heuristic analysis as potentially malicious. However, it doesn't necessarily confirm that the file is indeed a Trojan. It could be a false positive, where a legitimate program exhibits behavior that resembles malicious activity.

Fileloader.exe
Checked2024-04-20 14:15:52
MD5e5ef95312de9cb9a039be19f99a8aa36
SHA1ecaf6503b788a6e22249f1159ee9bffd75d152ee
SHA25635bbae9b61c149032032060d9eb855421acd23e1e97d27543258a1cc16203f74
SHA512d895a605ec94e319276efe43f806a9e0687307a33bb658649e8573e28d32e59f9cf7f9bd4c9fb9f7f36c74c68d5135e1d2b38cfa00c69fecb11d71bdc013529f
Imphash0d9e11188c37c5b1f5bbe92c282357b7
File Size17588224 bytes

Trojan.Heur!.02212023 Removal

Trojan.Heur!.02212023 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.02212023 without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

Portable Executable Info

Image Base:0x140000000
Entry Point:0x141b9dac2
Compilation:2024-04-20 13:05:38
Checksum:0x00000000 (Actual: 0x010ca4cc)
OS Version:6.0
PEiD:PE32+ executable (GUI) x86-64, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:10
Imports: d3d11, D3DCOMPILER_43, KERNEL32, USER32, ADVAPI32, SHELL32, ole32, WS2_32, CRYPT32, d3dx11_43, dwmapi, ntdll, IMM32,
Exports: 0
Resources:1

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x00411b88 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.rdata 0x00413000 0x0013f8be 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.data 0x00553000 0x001b263c 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.pdata 0x00706000 0x00024558 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
_RDATA 0x0072b000 0x000000f4 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.VAK0 0x0072c000 0x008eff19 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.VAK1 0x0101c000 0x00000ff0 0x00001000 4c0296b66cbb3099df7e7570f08d3339 0.23
.VAK2 0x0101d000 0x010c4628 0x010c4800 b491972798ea5ed515c58d8c6a3854d0 7.91
.reloc 0x020e2000 0x00000124 0x00000200 0d9eb8ffcc85165a4832e0b9f243dd84 2.86
.rsrc 0x020e3000 0x000001e0 0x00000200 81af53fda1f77d28388e5517a1d2e851 4.78

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware