EOSAuthHooker64.dll Trojan Heuristic Analysis

Trojan Heuristic
Updated on 2024-07-09 (11 days ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.181.174
DB Version:2024-07-09 03:00:33

Trojan.Heur!.022120A2

The "Heur" stands for "heuristic," which means we use a set of rules, algorithms, or behavioral analysis to detect potential threats that may not have a specific, known signature. It's a proactive approach to identifying suspicious behavior or code patterns that could indicate the presence of a Trojan or other malware. The file's behavior or characteristics triggered the heuristic analysis as potentially malicious. However, it doesn't necessarily confirm that the file is indeed a Trojan. It could be a false positive, where a legitimate program exhibits behavior that resembles malicious activity.

FileEOSAuthHooker64.dll
Checked2024-07-09 00:33:00
MD53d40e9e2c764c14b846431ae19cb0d4f
SHA149a147e0b68123fa9779f98a9da9d5f65a266342
SHA2566e544f4ffabc4dacacb84698764ae10cc90e5f8224806991d2dcefa98115be95
SHA51268ca849d927814a894c84521221c2b03a7125940dde403bc13b4a02ed18a4ee03343b18e72b7cbc0ec97bb5e829c0ef06385a249971a87330cab01f115950cc1
Imphash1ba7e4625aa59dfddbc799f4bff7a795
File Size3664384 bytes

Trojan.Heur!.022120A2 Removal

Trojan.Heur!.022120A2 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.022120A2 without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

CompanyNameOnline-Fix.Me
FileDescriptionEOS Auth Hooker
FileVersion1.1.0.0
LegalCopyrightCopyright (C) 2021-2022, 0xdeadc0de
ProductVersion1.1.0.0
Translation0x0407 0x04b0

Portable Executable Info

Image Base:0x180000000
Entry Point:0x1803d28ea
Compilation:2022-07-02 15:00:36
Checksum:0x00000000 (Actual: 0x003885f6)
OS Version:6.0
PEiD:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:10
Imports: KERNEL32, USER32, EOSSDK-Win64-Shipping,
Exports: 1
Resources:1

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x00011330 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.rdata 0x00013000 0x0000a0f8 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.data 0x0001e000 0x00001f70 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.pdata 0x00020000 0x00001464 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
_RDATA 0x00022000 0x0000015c 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.of0 0x00023000 0x00197aee 0x00000000 d41d8cd98f00b204e9800998ecf8427e 0.00
.of1 0x001bb000 0x00000680 0x00000800 e9d643624255d07a0bdf2131131c98ea 0.18
.of2 0x001bc000 0x0037d64c 0x0037d800 43af89b04427e897adbe0478de4886ee 7.79
.reloc 0x0053a000 0x000000d4 0x00000200 6d572aa5f214e2f681107443abda29a5 2.07
.rsrc 0x0053b000 0x00000288 0x00000400 2e2ccc4ab98f277e51bcec6f9b9dd522 2.24

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware