Gridinsoft Logo
File Icon

8187bb536c97c471ba17371542b1457c7392099735cd2afe817f9c04d5e4b196 Trojan Heuristic Analysis

Technical Analysis

File Name 8187bb536c97c471ba17371542b1457c7392099735cd2afe817f9c04d5e4b196
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.173.174
Database Version 2024-04-26 19:00:17 UTC

Trojan.Heur!.038100A3

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
8,063,728
File Size (bytes)
2024-04-26
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
3edb8bafa33b4b6d7029569f7fb43d73
SHA1
eb4888ccbc1bd3028310071420f297c005c495e9
SHA256
8187bb536c97c471ba17371542b1457c7392099735cd2afe817f9c04d5e4b196
SHA512
bad153fbd2ff3c753dfb67b63d3fbba85a595d18410bd2ffb88fed45d46f451f4555ad3c174157ab746d888360df9bc1bbdcea769b4f52d5fd7b7d2b98afb204
ImpHash
baa93d47220682c04d92f7797d9224ce

PE Analysis

Basic Information

Icon
Hash: 01a571f1f12f55f15016f9f38bf39f67
Fuzzy: 2e117022c440f79a7dad811e5a6841c9
dHash: b2aaccb2b2cce8b2
Image Base 0x140000000
Entry Point 0x1413b2000
Compilation Time 2019-01-30 17:56:21
Checksum 0x007bddbd (Actual: 0x007bddbd)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 2 libraries
kernel32, comctl32
Exports 0 functions
Resources 170 Resources
Sections 7 Sections

Version Information

Comments 一普明为Windows系统信息查看工具(安全类)
CompanyName 一普明为(北京)信息技术有限公司
FileDescription Epoolsoft Windows Information View Tools
FileVersion 1.0.0.5
InternalName PCHunter
LegalCopyright (C) 2013-2020 Epoolsoft Corporation. All Rights Reserved.
OriginalFilename PCHunter.exe
ProductName PC Hunter
ProductVersion 1.0.0.5
SpecialBuild 2019-01-30 Build
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 9,478,144 bytes 3,538,432 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3A50A363041BDD519982EE57C8802471
.rsrc 0x0090b000 2,033,279 bytes 856,576 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE DFE0A2FCF1567B6FC2785E683CBF5EAC
.idata 0x00afc000 4,096 bytes 512 bytes 1.30 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C1AE54473159B0462B344AEBA50C1AEE
0x00afd000 5,697,536 bytes 512 bytes 0.23 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE CD5C6EAD71C49495704058A57A086F8C
jmsnslzg 0x0106c000 3,432,448 bytes 3,431,936 bytes 7.95 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 23F1B154674CA60B192414B669AFC4C1
dlmuoaei 0x013b2000 4,096 bytes 512 bytes 4.64 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 499028D21AD83957B2D635879D5BFFBA
.pdataI 0x013b3000 217,088 bytes 217,088 bytes 6.48 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 81CA0A12F8B6FC6C82DD49E66793522D
Entropy Analysis Alert

3 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 170 (2,024,381 bytes)
Resource Type Count Total Size Percentage
KERNEL 3 1,867,480 bytes
92.2%
RT_CURSOR 17 5,108 bytes
0.3%
RT_BITMAP 3 109,188 bytes
5.4%
RT_ICON 15 15,512 bytes
0.8%
RT_DIALOG 87 22,158 bytes
1.1%
RT_STRING 14 2,774 bytes
0.1%
RT_GROUP_CURSOR 16 334 bytes
0%
RT_GROUP_ICON 13 288 bytes
0%
RT_VERSION 1 980 bytes
0%
RT_MANIFEST 1 559 bytes
0%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.038100A3 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.038100A3 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware