PS2TexRegionSwap.exe Malware Generic Analysis
Technical Analysis
| File Name | PS2TexRegionSwap.exe |
| File Type |
PE32+ executable (console) x86-64, for MS Windows
|
| Scanner Version | 1.0.237.174 |
| Database Version | 2026-02-03 22:00:19 UTC |
Malware.Win64.Generic.cld
Malware family: Generic
Scan Another File
File Identification
| Hash Type | Value | Action |
|---|---|---|
| MD5 |
3da024e423a570999466ba75bd7694e4
|
|
| SHA1 |
75205db67fe5fe3267daaf551ea3a4892871bdf7
|
|
| SHA256 |
573a8b085f5508db4c1e29f0b6be8cf41cbc30c0c34178367a8adf02c4dc090b
|
|
| SHA512 |
4ce4bc6b665f2b59c54cd5410f49d22e7264e69ba2637abd592e67411612d4ba525f05a7c8dd601b16307386e00891dc0de505c54318940aa4173ff14a73e07c
|
|
| ImpHash |
7f6ece173e25b4d3513563d487766e0a
|
PE Analysis
Basic Information
▼| Image Base | 0x140000000 |
| Entry Point | 0x14000134a |
| Compilation Time | 1970-01-01 00:00:00 |
| Checksum | 0x002bdcc6 (Actual: 0x002bdcc6) |
| OS Version | 4.0 |
| PEiD Signatures |
PE32+ executable (console) x86-64, for MS Windows
|
| Digital Signature | No valid SignedData structure was found. |
| Imports |
2 libraries
KERNEL32, msvcrt |
| Exports | 0 functions |
| Resources | 0 Resources |
| Sections | 17 Sections |
PE Sections
▼| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
|---|---|---|---|---|---|---|
.text |
0x00001000 |
611,520 bytes | 611,840 bytes | 6.18 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
B080EEC445728744C0283F6E87B09957 |
.data |
0x00097000 |
12,544 bytes | 12,800 bytes | 0.40 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
97E8FBB1B8F18F897B7F8EA180C37EA7 |
.rdata |
0x0009b000 |
78,232 bytes | 78,336 bytes | 4.91 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
22D9C04360AA721B63776354403099D5 |
.pdata |
0x000af000 |
56,760 bytes | 56,832 bytes | 5.96 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
DB6ACE166E73037913A250A66D96F01B |
.xdata |
0x000bd000 |
66,528 bytes | 66,560 bytes | 4.75 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
35A99C9856C64155D7D174469D3F8B10 |
.bss |
0x000ce000 |
3,312 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x000cf000 |
6,344 bytes | 6,656 bytes | 4.01 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
0EE9F17CBA8B8C388BAAA56403ACE06F |
.tls |
0x000d1000 |
16 bytes | 512 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
BF619EAC0CDF3F68D496EA9344137E8B |
.reloc |
0x000d2000 |
5,944 bytes | 6,144 bytes | 5.40 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
23B18AB550A445943C84922D93CE9129 |
/4 |
0x000d4000 |
176 bytes | 512 bytes | 0.62 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
9A66B3D66B359DE9D6FF6DABA2CE2668 |
/19 |
0x000d5000 |
18,956 bytes | 19,456 bytes | 5.77 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
5F0EEE2BDF1941A79E0BEF24FF3F4A04 |
/31 |
0x000da000 |
2,118 bytes | 2,560 bytes | 4.38 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
98FB64F9EC8915CB5A4825473806EF6B |
/45 |
0x000db000 |
2,249 bytes | 2,560 bytes | 4.53 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
24C1C639C845C5230CDAD32A327D2C72 |
/57 |
0x000dc000 |
984 bytes | 1,024 bytes | 3.71 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
910FC771706C9209441EE696900FEE7A |
/70 |
0x000dd000 |
168 bytes | 512 bytes | 2.41 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
9AA1300C4B0DBE0C00F10B4E8C95FDB1 |
/81 |
0x000de000 |
738 bytes | 1,024 bytes | 4.02 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
5AA18A68CA55C8CD2BEAFF478B877B8E |
/97 |
0x000df000 |
1,541 bytes | 2,048 bytes | 3.95 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
9913D469AC9DFAE143CD8F39B5B06257 |
Certificate Chain Analysis
▼No Digital Signatures
This file is not digitally signed.
Security Implications:
- Cannot verify the publisher's identity
- Increased security risk when running this file
- May trigger security warnings on some systems
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
Certificate Verification Status
No valid SignedData structure was found.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Malware.Win64.Generic.cld Removal
Gridinsoft has the capability to identify and eliminate Malware.Win64.Generic.cld without requiring further user intervention.
Download Anti-Malware
Removal Instructions
Follow these steps to completely remove the threat from your system
-
1
Get Gridinsoft Anti-Malware — it's a quick 2 MB download that won't slow down your PC.
-
2
Run the installer gsam-en-install.exe. The setup takes about 2 minutes and doesn't require a restart.
-
3
The app launches right after installation. You'll see the main dashboard with the scan button front and center.
-
4
Hit "Standard Scan" — this checks all the spots where malware typically hides: temp folders, browser data, startup programs, and system directories.
-
5
Once the scan finds this threat, click "Clean Now". The removal usually happens instantly, though some stubborn infections may need a reboot.
-
6
If you see a restart prompt, go ahead and reboot. This clears any malware that was running in memory and ensures your system starts fresh.
Leave a Comment
Gridinsoft Anti-Malware
Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware
Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!