Gridinsoft Logo

CLDeanon.exe Trojan Heuristic Analysis

Technical Analysis

File Name CLDeanon.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.179.174
Database Version 2024-06-14 17:00:18 UTC

Trojan.Heur!.00002031

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
27,262,976
File Size (bytes)
2024-06-14
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
89ec08f06ab3a48b17461901a840e728
SHA1
a5aace8bb6e64b0cc03624d0ee67ad9ecc191b18
SHA256
4e043542639b4aa669ead0bafe18c865d250e60b376fdfc3249a12b1d30586a1
SHA512
b4a349d96d15699adfe9a00ae27a982ef49783b4c14713e081a1b964fbbc78f3aafe2dc65a041b2c571ebecc0f5e40f43ba0f77e290fd6472154d5d7bf3018ec
ImpHash
7104476aa32cf4b45f58ce5b636dd82a

PE Analysis

Basic Information

Image Base 0x00400000
Entry Point 0x004011ea
Compilation Time 2023-10-24 10:27:33
Checksum 0x00000000 (Actual: 0x01a09f75)
OS Version 6.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path C:\A10\m82f1\output.pdb
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 2 libraries
USER32, KERNEL32
Exports 0 functions
Resources 0 Resources
Sections 8 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 706,132 bytes 706,560 bytes 5.74 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 215F39379CB16FDBA41E9606C0571CD2
.rdata 0x000ae000 113,961 bytes 114,176 bytes 4.07 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ A1A3F26FD3AB0C1C5744B2B900AFF343
.data 0x000ca000 20,752 bytes 12,800 bytes 3.75 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 839BC5887C318D2AC557DA071AC1E0D9
.idata 0x000d0000 4,892 bytes 5,120 bytes 4.77 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6872CA9F08F8F0BF4BFC532607518962
.111 0x000d2000 170,923 bytes 171,008 bytes 6.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 156982D1D7CB861E2E32D6627FC6AE7A
.tls 0x000fc000 777 bytes 1,024 bytes 0.01 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C573BD7CEA296A9C5D230CA6B5AEE1A6
.00cfg 0x000fd000 270 bytes 512 bytes 0.11 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 0D11B4C081005B4BF744A5A3F51C1A2F
.reloc 0x000fe000 24,182 bytes 24,576 bytes 6.10 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ E6887E57B3B1CBB23F5126CDFD518992

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.00002031 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.00002031 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware