Gridinsoft Logo

Frpc.exe Virtool Gen Analysis

Technical Analysis

File Name frpc.exe
File Type
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Scanner Version 1.0.155.174
Database Version 2024-01-18 05:02:06 UTC

Virtool.Win64.Gen.cl

Malware family: Gen

This is a generic detection identifier for files exhibiting Trojan horse characteristics. It indicates malware that disguises itself as legitimate software while containing malicious code designed to compromise system security or steal information.
N/A
Detection Rate
11,140,608
File Size (bytes)
2024-01-18
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
7d9c233b8c9e3f0ea290d2b84593c842
SHA1
06ddc9280e1f1810677935a2477012960905942f
SHA256
57b0936b8d336d8e981c169466a15a5fd21a7d5a2c7daf62d5e142ee860e387c
SHA512
d000e061a11bcd82abf986bd09d87abc7429e38fb2d1699cdfa126b0dac88a6c7429aeb6f9b4737d1dc59d8b21a90c4fe6bcf1923955f9f43f8674094a8de603
ImpHash
ff9f3a86709796c17211f9df12aae74d

PE Analysis

Basic Information

Image Base 0x00400000
Entry Point 0x0046b0a0
Compilation Time 1970-01-01 00:00:00
Checksum 0x00000000 (Actual: 0x00aacd60)
OS Version 6.1
PEiD Signatures PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 1 libraries
kernel32
Exports 0 functions
Resources 0 Resources
Sections 6 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 5,053,160 bytes 5,053,440 bytes 6.15 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 3AFEDAFB82C1CFE5D220BD767854DF93
.rdata 0x004d3000 5,617,360 bytes 5,617,664 bytes 5.87 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B539FB19F5475CEA344B5484BF0E7395
.data 0x00a2f000 827,440 bytes 384,000 bytes 5.84 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4A8B3885AB68E4E1986DE0A58AB98DF3
.idata 0x00afa000 1,208 bytes 1,536 bytes 3.72 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2D407AE53346DCFDCCC3560B35EB3C87
.reloc 0x00afb000 81,424 bytes 81,920 bytes 5.44 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 16A967AE8FE0E8B4DB3B09A26E46B8BD
.symtab 0x00b0f000 4 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 07B5472D347D42780469FB2654B7FC54

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Virtool.Win64.Gen.cl Removal

Gridinsoft has the capability to identify and eliminate Virtool.Win64.Gen.cl without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware