Gridinsoft Logo
File Icon

小鲁温度监控 v2.0.0.1001 单文件独立版.exe Malware Gen Analysis

Technical Analysis

File Name 小鲁温度监控 v2.0.0.1001 单文件独立版.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.215.174
Database Version 2025-04-29 23:00:20 UTC

Malware.Win32.Gen.cc!s1

Malware family: Gen

This is a generic detection identifier for files exhibiting Trojan horse characteristics. It indicates malware that disguises itself as legitimate software while containing malicious code designed to compromise system security or steal information.
N/A
Detection Rate
11,749,153
File Size (bytes)
2025-04-30
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
bed06c1bb672ece1dc6428cc618d6f21
SHA1
fff0244bb28f03ac461e3d5eaae927675aa45761
SHA256
8cc5a8c60670fe424f6a821927baf483047b2b815e0681e580ad167d59c51517
SHA512
662242567db95fc0406fbc8cd93fab1a67b55b546da8a2240dac81c65c8932d0688fbb1f5a067a3b626e6c0b7a350192d54c0cb416fcabbc3d3e54e72a8207a6
ImpHash
de1fa96ad5bc81910ffb7ed552e29d0d

PE Analysis

Basic Information

Icon
Hash: 2bf3a2f17dda742e602cf679d02b0e98
Fuzzy: 7f5a48b856b37787baf3a9e5f979a764
dHash: b0f17171b96d69b1
Image Base 0x00400000
Entry Point 0x0041a238
Compilation Time 1992-06-19 22:22:17
Checksum 0x00b3b97f (Actual: 0x00b3b97f)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 6 libraries
kernel32, user32, advapi32, oleaut32, gdi32, shell32
Exports 0 functions
Resources 18 Resources
Sections 8 Sections

Version Information

CompanyName 不再孤独-制作
FileDescription 小鲁温度监控 独立版
FileVersion 2, 0, 0, 1001
InternalName LdsLite.exe
LegalCopyright QQ:1294025141
OriginalFilename LdsLite.exe
ProductName 小鲁温度监控 独立版
ProductVersion 2, 0, 0, 1001
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
CODE 0x00001000 107,440 bytes 107,520 bytes 6.51 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 88CE445F0F1DC01B5B1FB53A086E1D84
DATA 0x0001c000 3,356 bytes 3,584 bytes 4.44 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E2A58858CDAA51C054B08E04A5672E7F
BSS 0x0001d000 10,493,445 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x00a1f000 3,780 bytes 4,096 bytes 4.63 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8E9B96D27CE8C9EC77E33F3A176D299F
.tls 0x00a20000 12 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rdata 0x00a21000 37 bytes 512 bytes 0.41 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ 07E697B88756B2C1408C4FCADE2A25A4
.reloc 0x00a22000 7,692 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.rsrc 0x00a24000 62,296 bytes 62,464 bytes 3.58 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ 93F2C98FEEB5ECBD24DFE2705947CF25
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 18 (61,192 bytes)
Resource Type Count Total Size Percentage
RT_ICON 5 55,528 bytes
90.7%
RT_STRING 7 4,116 bytes
6.7%
RT_RCDATA 3 308 bytes
0.5%
RT_GROUP_ICON 1 76 bytes
0.1%
RT_VERSION 1 744 bytes
1.2%
RT_MANIFEST 1 420 bytes
0.7%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Malware.Win32.Gen.cc!s1 Removal

Gridinsoft has the capability to identify and eliminate Malware.Win32.Gen.cc!s1 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware