File Name | vcruntime140.dll |
File Type |
PE32+ executable (DLL) (console) x86-64, for MS Windows
|
Scanner Version | 1.0.221.174 |
Database Version | 2025-07-23 14:00:30 UTC |
Malware family: Heuristic
Hash Type | Value | Action |
---|---|---|
MD5 |
aa4ff742fd13c70260c2142c01f17086
|
|
SHA1 |
7b7f75e301de62f628438080cddfc00e39876e62
|
|
SHA256 |
b2e1c47e195a27c129a8aa036186582d045e7e8805d7c1ff1d1cf1947c651aa4
|
|
SHA512 |
9aad4b070554dba76e72949a82206ed1862705a636f49f10dcac348cc428ae658524aaafa34ce9db68cf10a791cd9978ca0d3d289acff8f6ee7f2221af2403fa
|
|
ImpHash |
4a020c7afafad4e9fdfde1def9f416b8
|
Image Base | 0x180000000 |
Entry Point | 0x180596058 |
Compilation Time | 2021-07-26 21:27:40 |
Checksum | 0x0033add3 (Actual: 0x0033add3) |
OS Version | 6.0 |
PEiD Signatures |
PE32+ executable (DLL) (console) x86-64, for MS Windows
|
Digital Signature | No valid SignedData structure was found. |
Imports |
6 libraries
kernel32, api-ms-win-crt-runtime-l1-1-0, api-ms-win-crt-heap-l1-1-0, api-ms-win-crt-string-l1-1-0, api-ms-win-crt-stdio-l1-1-0, api-ms-win-crt-convert-l1-1-0 |
Exports | 71 functions |
Resources | 1 Resources |
Sections | 12 Sections |
CompanyName | Microsoft Corporation |
FileDescription | Microsoft® C Runtime Library |
FileVersion | 14.29.30133.0 built by: vcwrkspc |
InternalName | vcruntime140.dll |
LegalCopyright | © Microsoft Corporation. All rights reserved. |
OriginalFilename | vcruntime140.dll |
ProductName | Microsoft® Visual Studio® |
ProductVersion | 14.29.30133.0 |
Translation | 0x0409 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
|
0x00001000 |
63,650 bytes | 34,768 bytes | 7.97 (Packed/Encrypted) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
4CF496BE9A010DF3218BD7E81D949B23 |
|
0x00011000 |
16,618 bytes | 5,934 bytes | 7.90 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
3B9BF89A996040B1FE2733D3A4F946A2 |
|
0x00016000 |
2,368 bytes | 196 bytes | 6.81 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
1D4B6CD5F848CD403C7195F134805FF1 |
|
0x00017000 |
2,904 bytes | 1,648 bytes | 7.65 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
CD50D73F3EC98E47D4396D1D2395EF30 |
|
0x00018000 |
244 bytes | 138 bytes | 6.49 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
222C56F9A78F4B8DF61FB5BE17736276 |
|
0x00019000 |
1,016 bytes | 439 bytes | 7.49 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
50C8B12F03C245A0CD80521E9455007D |
|
0x0001a000 |
416 bytes | 388 bytes | 6.22 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
E0E353FBFF871675022EA188DFBE97AC |
.exports |
0x0001b000 |
4,096 bytes | 2,560 bytes | 4.74 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
DD21C67EB11801B342BCF8ABF5BB2291 |
.imports |
0x0001c000 |
4,096 bytes | 512 bytes | 3.71 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
AAC0F9DB62D25E1D870F886B70AEF9B6 |
.rsrc |
0x0001d000 |
4,096 bytes | 1,024 bytes | 3.33 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
AA8AACA792D40C30CABF65114E5CFE18 |
.themida |
0x0001e000 |
5,734,400 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.boot |
0x00596000 |
3,291,136 bytes | 3,290,712 bytes | 7.96 (Packed/Encrypted) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
34B26A80C5BD4A11741589610EAC926B |
4 section(s) with high entropy (≥7.5) detected - possible packing/encryption
2 section(s) with elevated entropy (≥6.5) - possible compression
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_VERSION | 1 | 916 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
No valid SignedData structure was found.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft has the capability to identify and eliminate Trojan.Heur!.032100A2 without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system