File Name | kds3.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.215.174 |
Database Version | 2025-04-24 05:00:18 UTC |
Malware family: Heuristic
Hash Type | Value | Action |
---|---|---|
MD5 |
792d563cece887bda86db73cad20ba35
|
|
SHA1 |
1b713713b0a8ecdf6637475548d5195e40d0b7f4
|
|
SHA256 |
60fb0cb9ba41d636a29be0547c0cd46f0f8374ba47e0b2604f6ab66d84be84a0
|
|
SHA512 |
3a4ed1a4eb2c7682438aaabf802989729c3ae3b85e86e4686ada182f27d57b7cfcf615c4ee92d8d5acbd97fc80aaaba20912fd7833f3c906c20b5ca3f1805bfa
|
|
ImpHash |
111b34f4048626d3fde36e925a6151e3
|
Icon |
Hash: 2ab17cabd963f9e4209b9da4dc72462d
Fuzzy: d19a7def2cf0693ac5fa5f0e9db6fc7f dHash: 4c9e161712328cec |
Image Base | 0x00400000 |
Entry Point | 0x00d7a000 |
Compilation Time | 1998-04-22 02:53:33 |
Checksum | 0x0014fe31 (Actual: 0x0014fe31) |
OS Version | 4.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | Chain verification from CN=Protection Technology\, Ltd., OU=Software Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Protection Technology\, Ltd., L=Moscow, ST=Not present, C=RU (serial:59936359943326187818286869077043090556, sha1:404820d0a0b9f5dbad49c12bce96d66f10feb232) failed: The path could not be validated because intermediate certificate 1 expired 2009-07-15 23:59:59Z |
Imports | 16 libraries |
Exports | 0 functions |
Resources | 7 Resources |
Sections | 6 Sections |
CompanyName | VZlab Co Ltd |
FileDescription | VZEngine |
FileVersion | 1, 1, 6, 100 |
InternalName | VZEngine |
LegalCopyright | Copyright 2003-2005 VZlab Co Ltd. |
LegalTrademarks | VZlab Co Ltd. |
OriginalFilename | fullscreen.exe |
ProductName | VZEngine |
ProductVersion | 1, 1, 6, 100 |
Translation | 0x0419 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.sforce3 |
0x00001000 |
1,219,040 bytes | 1,219,040 bytes | 8.00 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
A73B16F81EFE517ACC0057160A6ED8D9 |
.idata |
0x0012b000 |
20 bytes | 20 bytes | 1.66 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D537379D707CB009A1D737CFB1CBBBA1 |
.brick |
0x0012c000 |
8,593,408 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rsrc |
0x0095e000 |
113,640 bytes | 113,640 bytes | 6.92 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
7CFBF32365DEACE7C7E5CC5BC23D54D7 |
.start |
0x0097a000 |
4,096 bytes | 4,096 bytes | 1.35 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
E951F6747F83DB373F0A38A6F673DDCD |
.brick |
0x0097b000 |
86,016 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
1 section(s) with high entropy (≥7.5) detected - possible packing/encryption
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_BITMAP | 1 | 107,508 bytes | |
RT_ICON | 1 | 2,216 bytes | |
RT_DIALOG | 3 | 2,582 bytes | |
RT_GROUP_ICON | 1 | 20 bytes | |
RT_VERSION | 1 | 812 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
Chain verification from CN=Protection Technology\, Ltd., OU=Software Development, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Protection Technology\, Ltd., L=Moscow, ST=Not present, C=RU (serial:59936359943326187818286869077043090556, sha1:404820d0a0b9f5dbad49c12bce96d66f10feb232) failed: The path could not be validated because intermediate certificate 1 expired 2009-07-15 23:59:59Z
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft has the capability to identify and eliminate Trojan.Heur!.01210131 without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system