Gridinsoft Logo
File Icon

The AndrowsInstaller.exe (腾讯应用宝) File Analysis

Technical Analysis

File Name AndrowsInstaller.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.223.174
Database Version 2025-08-25 12:00:40 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
6,723,768
File Size (bytes)
2025-08-25
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
6e6afd33e178857de4b384e83b22cf49
SHA1
1f191ac5b58d3644e819110c8ad09f27a8a96971
SHA256
55a446308f777a478ea79f4296a4d8d898fc7882cc6472535afc6887372de8f6
SHA512
d81cae82544fb06b25e7f5aaf44386464b5cc3f4e42a479bf31b46717715c01da48e8b65ea4fd13cd2dfe0e2db443aa49f08e7c6cf6b84a36b1a2466451ec743
ImpHash
ace5257a77697146cf79b1309ec4dcc3

PE Analysis

Basic Information

Icon
Hash: 5d01bd2cedae64997df260f8c17783ed
Fuzzy: 7e5736be62a3d55cba21787eea828530
dHash: cc27337171331acc
Image Base 0x140000000
Entry Point 0x1402e819c
Compilation Time 2023-09-09 07:24:03
Checksum 0x0066d0f9 (Actual: 0x0066d0f9)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
PDB Path E:\workplace\Androws\p-4ff796941325489e9c426b6fb216f108\build\bin\Release\AndrowsInstaller.pdb
Digital Signature OK
Imports 19 libraries
Exports 0 functions
Resources 11 Resources
Sections 8 Sections

Version Information

CompanyName Tencent
FileDescription 腾讯应用宝
FileVersion 1.0.1489.0
LegalCopyright Copyright (C) 2022 Tencent. All Rights Reserved.
InternalName Androws
ProductName Androws
ProductVersion 1.0.1489.0
Translation 0x0000 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 3,359,808 bytes 3,360,256 bytes 6.52 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 9EA61A6B99932E2FE93B33B3C2FE777F
.rdata 0x00336000 1,035,228 bytes 1,035,264 bytes 6.13 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D1D9BD91B5DD75F7DDDBA6BB262B0117
.data 0x00433000 238,020 bytes 211,456 bytes 5.04 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 10171AE487467590651A76B854205C24
.pdata 0x0046e000 149,040 bytes 149,504 bytes 6.36 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ EAF20EADCE37F13156C86544E24D31BA
_RDATA 0x00493000 244 bytes 512 bytes 2.41 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7CFFC0BAD3DD4550C304F9C59F413DF7
.QMGuid 0x00494000 32 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x00495000 1,920,144 bytes 1,920,512 bytes 6.38 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 68BC099E856AE060EF0EE78E9C3C9FD5
.reloc 0x0066a000 35,100 bytes 35,328 bytes 5.46 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 79B6721F83883261CB145F2E1BA32A4B
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 11 (1,919,405 bytes)
Resource Type Count Total Size Percentage
CUSTOM 1 1,679,360 bytes
87.5%
ZIPRES 1 133,126 bytes
6.9%
RT_ICON 6 105,508 bytes
5.5%
RT_GROUP_ICON 1 90 bytes
0%
RT_VERSION 1 668 bytes
0%
RT_MANIFEST 1 653 bytes
0%

Certificate Chain Analysis

Certificate Information
Product Androws
Description 腾讯应用宝
File Version 1.0.1489.0
Signing Date 05:03 AM 02/04/2024 (853 days ago)
Verification Status Signed
Signers Tencent Technology(Shenzhen) Company Limited; DigiCert SHA2 Assured ID Code Signing CA; DigiCert
Counter Signers DigiCert Timestamp 2023; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Internal Name Androws
Copyright Copyright (C) 2022 Tencent. All Rights Reserved.
Certificate Chain Summary
DigiCert SHA2 Assured ID Code Signing CA #1 Primary
Validity Period: 2013-10-22 12:00:00 → 2028-10-22 12:00:00
Signature Algorithm: sha256RSA
Serial Number: 04 09 18 1B 5F D5 BB 66 75 53 43 B5 6F 95 50 08
Tencent Technology(Shenzhen) Company Limited #2 Chain
Validity Period: 2020-11-25 00:00:00 → 2024-02-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0E A7 F6 86 BC 40 35 4A 70 F2 C2 97 C1 31 5E F6
DigiCert Timestamp 2023 #3 Chain
Validity Period: 2023-07-14 00:00:00 → 2034-10-13 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 05 44 AF F3 94 9D 08 39 A6 BF DB 3F 5F E5 61 16
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #4 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted Root G4 #5 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. 1
    Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
  2. 2
    Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
  3. 3
    Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
  4. 4
    Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Proactive Protection
This file looks clean right now, but that doesn't mean you should let your guard down. New malware appears daily, and even legit files can be compromised after download. When in doubt, verify the source and check for a digital signature.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware