Visualcam exe Trojan Heuristic File Malware Analysis: 8f4ffa6adc4c9cd0da2af39ddf877ef6
Gridinsoft Logo
File Icon

Visualcam.exe Trojan Heuristic Analysis

Technical Analysis

File Name visualcam.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.223.174
Database Version 2025-08-24 10:00:41 UTC

Trojan.Heur!.00046033

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
15,943,384
File Size (bytes)
2025-08-24
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
8f4ffa6adc4c9cd0da2af39ddf877ef6
SHA1
1e99a2e92d3ddd0e3ead69e35a67e00810f66ff2
SHA256
3d9701775b0bc2fdca70b0a0750769151a3969d46de40c1d02df3619e49c7b5b
SHA512
0eba8f498d7bcf51d88b3c33aea3b1366b67a917d2250bac944072b4ea8434aaa2be3ddae951ee28c1b6d75e0ea13659fe3c90ee2825e8a0b9db45becd48be8d
ImpHash
82eeb5f4f2ca21d99c9c5c8fdab769d7

PE Analysis

Basic Information

Icon
Hash: bdb27dd80cfb08c4d0db17ecd400be5c
Fuzzy: 182d7c9d8aef42176cebd559904a3dd2
dHash: ccbb4d686a33b3e8
Image Base 0x140000000
Entry Point 0x1407696f8
Compilation Time 2019-01-11 20:13:52
Checksum 0x00f3d0a2 (Actual: 0x00f445c0)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 45 libraries
Exports 1121 functions
Resources 864 Resources
Sections 8 Sections

Version Information

CompanyName WISE Software Solutions, Inc.
FileDescription VisualCAM Executable
FileVersion 16.9.69.0
InternalName VisualCAM
LegalCopyright Copyright © 1989-2018 WISE Software Solutions, Inc.
LegalTrademarks VisualCAM, GerbTool, esiCAM, LaserViaCAM and WiseView are trademarks of WISE Software Solutions, Inc.
OriginalFilename VisualCAM.exe
ProductName WISE Software VisualCAM
ProductVersion 16.9.0.0
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 8,788,476 bytes 8,788,480 bytes 6.38 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 9D997E36BEF8A36BC3564F5CF92458CB
.textidx 0x00863000 1,194,637 bytes 1,195,008 bytes 5.50 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 7FECA97959C5DC308FE17C1284AC6BF5
.rdata 0x00987000 3,750,974 bytes 3,751,424 bytes 5.16 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 64519D9D2C09BD1C68BCFFCD9D245DAF
.data 0x00d1b000 1,602,604 bytes 861,184 bytes 4.82 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 661CC6B2CBB11ECF91D1D3973D21A9C6
.pdata 0x00ea3000 452,736 bytes 453,120 bytes 6.51 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ CEABDDCC34F77708DEA1B26B9E771730
.gfids 0x00f12000 68 bytes 512 bytes 0.35 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9C3EF078DFB29C07117F884FD0AC1785
.tls 0x00f13000 9 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1F354D76203061BFDD5A53DAE48D5435
.rsrc 0x00f14000 884,000 bytes 884,224 bytes 5.41 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ FC7945B13DBA49A5F3E2EC73ED3079F9
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 864 (840,059 bytes)
Resource Type Count Total Size Percentage
AFX_DIALOG_LAYOUT 30 60 bytes
0%
RT_CURSOR 10 3,136 bytes
0.4%
RT_BITMAP 71 325,880 bytes
38.8%
RT_ICON 142 150,182 bytes
17.9%
RT_MENU 5 21,744 bytes
2.6%
RT_DIALOG 346 271,950 bytes
32.4%
RT_STRING 88 56,872 bytes
6.8%
RT_ACCELERATOR 1 48 bytes
0%
RT_GROUP_CURSOR 7 182 bytes
0%
RT_GROUP_ICON 132 2,780 bytes
0.3%
RT_VERSION 1 1,088 bytes
0.1%
RT_MANIFEST 1 798 bytes
0.1%
None 30 5,339 bytes
0.6%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.00046033 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.00046033 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware