Online Virus Checker | v.1.0.216.174 |
DB Version: | 2025-05-16 02:00:24 |
The "Heur" stands for "heuristic," which means we use a set of rules, algorithms, or behavioral analysis to detect potential threats that may not have a specific, known signature. It's a proactive approach to identifying suspicious behavior or code patterns that could indicate the presence of a Trojan or other malware. The file's behavior or characteristics triggered the heuristic analysis as potentially malicious. However, it doesn't necessarily confirm that the file is indeed a Trojan. It could be a false positive, where a legitimate program exhibits behavior that resembles malicious activity.
File | launcher.exe |
Checked | 2025-05-15 23:23:38 |
MD5 | 17f5c73c78064cfbbd17516cf89ad7ee |
SHA1 | 72cd9dadce5e5d35ba06ceec425a237f85a7e276 |
SHA256 | 92a4ea6ebc752eccd5c7afbcd1ba176a24795ab93cc800c6a013a48a8174b4e9 |
SHA512 | 8f4e8bc16babefb8ec599a91f996d0a4089b1d466cdd7440171e0759907852df6038451b04506f4afabdd8bdf21f00d320f556bef4f294b3a4f3af41e7180903 |
Imphash | 5331016eb8f43aa420cbb468154138ed |
File Size | 73437696 bytes |
Gridinsoft has the capability to identify and eliminate Trojan.Heur!.022120A3 without requiring further user intervention.
1e781df5791bafffbbc09282d936cce3 b55fcad2ed87b93df2ecc71a5e805980 87135bc9c9b9b316 |
|
Image Base: | 0x140000000 |
Entry Point: | 0x1440ed727 |
Compilation: | 2025-05-07 15:46:30 |
Checksum: | 0x00000000 (Actual: 0x046129dc) |
OS Version: | 6.0 |
PEiD: | PE32+ executable (console) x86-64, for MS Windows |
Sign: | No valid SignedData structure was found. |
Sections: | 8 |
Imports: | KERNEL32, COMDLG32, ADVAPI32, MSVCP140, VCRUNTIME140_1, VCRUNTIME140, api-ms-win-crt-runtime-l1-1-0, api-ms-win-crt-stdio-l1-1-0, api-ms-win-crt-filesystem-l1-1-0, api-ms-win-crt-string-l1-1-0, api-ms-win-crt-heap-l1-1-0, api-ms-win-crt-math-l1-1-0, api-ms-win-crt-convert-l1-1-0, api-ms-win-crt-locale-l1-1-0, |
Exports: | 0 |
Resources: | 3 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000231df | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.rdata | 0x00025000 | 0x0000a3f4 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.data | 0x00030000 | 0x00001208 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.pdata | 0x00032000 | 0x00001d88 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.shika0 | 0x00034000 | 0x03c72b21 | 0x00000000 | d41d8cd98f00b204e9800998ecf8427e | 0.00 |
.shika1 | 0x03ca7000 | 0x00000110 | 0x00000200 | be5be3ee1386b9796c6c3f7404444496 | 1.02 |
.shika2 | 0x03ca8000 | 0x045f7ec0 | 0x045f8000 | c5ce19b1492b5866d3a4a93ca38c2a24 | 7.94 |
.rsrc | 0x082a0000 | 0x00010ab0 | 0x00010c00 | e0b8056ad342e553e1ba927bac1bd823 | 6.42 |