Gridinsoft Logo

Bootstrapper.exe Stealer Gen Analysis

Stealer Gen
Updated on 2024-08-31 (4 months ago)
Checked by Online Virus Scanner
Online Virus Checker v.1.0.185.174
DB Version: 2024-08-31 19:00:36

Spy.Win32.Gen.tr

This is a generic detection name used to identify a potentially harmful or suspicious file or program that exhibits characteristics of a Trojan horse. It is malware that disguises itself as a legitimate or benign program but contains malicious code or functions.

File Bootstrapper.exe
Checked 2024-08-31 16:53:22
MD5 7776882352548456cfc6f9827572d724
SHA1 22785b7dac19933527255ef7a96fb331f7a455a5
SHA256 6a850e209de722ad4f57dd68f8af405d62ad6557772717bbd86052d1fe43910f
SHA512 9d0cdc083f75bf524484c231a69e5179bdcc6a6b4ab845ede88aa9ef0f336b0d3d67e90752c545272958f82d8f4fdd1293bd070bd56a3cadaa252d2b53e864e2
Imphash f34d5f2d4577ed6d9ceec516c1f5a744
File Size 106496 bytes

Spy.Win32.Gen.tr Removal

Spy.Win32.Gen.tr Removal

Gridinsoft has the capability to identify and eliminate Spy.Win32.Gen.tr without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

Translation 0x0000 0x04b0
Comments
CompanyName
FileDescription debug
FileVersion 1.0.0.0
InternalName debug.exe
LegalCopyright Copyright © 2024
LegalTrademarks
OriginalFilename debug.exe
ProductName debug
ProductVersion 1.0.0.0
Assembly Version 1.0.0.0

Portable Executable Info

ad4b91ccaba55db972bf3df769546f0d
4dbcd8e2b7a82acd1c92ab1089777f68
e896334d692b864c
Image Base: 0x00400000
Entry Point: 0x00415f7e
Compilation: 2073-01-17 21:19:41
Checksum: 0x00024c79 (Actual: 0x00024c79)
OS Version: 4.0
PDB Path: C:\Users\danie\source\repos\debug\debug\obj\Debug\debug.pdb
PEiD: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Sign: The PE file does not contain a certificate table.
Sections: 3
Imports: mscoree,
Exports: 0
Resources: 4

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00002000 0x00013f84 0x00014000 a5f0ccc5f8b453d684e023e71c812853 7.54
.rsrc 0x00016000 0x00005a12 0x00005c00 6b12ce90c2f9a3f51b2524408e9041c5 7.79
.reloc 0x0001c000 0x0000000c 0x00000200 3c46560f4080ef1e522c2a8b53f990d4 0.10

Leave a comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware