Gridinsoft Logo
File Icon

AndroidEmulatorEn.exe Trojan Heuristic Analysis

Technical Analysis

File Name AndroidEmulatorEn.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.212.174
Database Version 2025-04-05 12:00:47 UTC

Trojan.Heur!.00212031

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
6,740,936
File Size (bytes)
2025-04-05
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
ef1159cb9f26fd7308533a423c65ede3
SHA1
ed002d46a58ed58ef8bbb8b1b4b453ba37524d79
SHA256
b72325fe4c00e3fc530c95f45192f3d9659fe69c1f408453279e9c6f2d79e288
SHA512
35645f28dbada62e60c47835439a302c8e38797f1a872f830f82d51139322af98c891692a441608ef906919fa12b8baee2dabcc32fefc31abbb11c55b0973b2c
ImpHash
91e264b7752a402e20bbbd5b425cc0ad

PE Analysis

Basic Information

Icon
Hash: ee362821f8db9bb96bbf8ed5d59b2822
Fuzzy: 4b037942d6ce64ffee862f3b5322bb41
dHash: e0cc8e0f0fa6f8f0
Image Base 0x00400000
Entry Point 0x007c0d55
Compilation Time 2021-10-01 07:10:58
Checksum 0x0066fe55 (Actual: 0x00676bc7)
OS Version 5.1
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path E:\workp
Digital Signature The expected hash does not match the digest in SpcInfo
Imports 3 libraries
ntdll, KERNEL32, WS2_32
Exports 0 functions
Resources 11 Resources
Sections 13 Sections

Version Information

CompanyName Tencent
FileDescription Gameloop
FileVersion 3.21.4638.80
InternalName AndroidEmulator
LegalCopyright Copyright © 2020 Tencent. All Rights Reserved.
OriginalFilename AndroidEmulator.exe
ProductName Gameloop
ProductVersion 3,21,4638,80
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 1,912,267 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.rdata 0x001d4000 685,564 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.data 0x0027c000 143,164 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.gfids 0x0029f000 92 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.tls 0x002a0000 9 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rsrc 0x002a1000 412,664 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.tvm0 0x00306000 196,608 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D41D8CD98F00B204E9800998ECF8427E
.rsrc 0x00336000 412,664 bytes 412,672 bytes 5.25 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ AE4D032626143F9D10A698168670ED63
.ace0 0x0039b000 670,811 bytes 671,232 bytes 7.31 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 67F8B22456BA522C6252185E04AF58AC
.ace1 0x0043f000 250,824 bytes 250,880 bytes 5.57 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE C24F79EDC7C0225C1545115FB7CF7092
.ace2 0x0047d000 3,211,264 bytes 3,208,704 bytes 7.41 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 17C2AF228D64F62EB66C8E395C1925B4
.ace3 0x0078d000 2,165,302 bytes 2,165,760 bytes 7.13 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE CB61696A05FEB7CA8AB74DA5F59B5E48
.reloc 0x0099e000 16,536 bytes 16,896 bytes 6.22 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 7C459FBCA350047B4A3EA43AB3E2BA6C
Entropy Analysis Alert

3 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 11 (412,013 bytes)
Resource Type Count Total Size Percentage
RT_ICON 8 410,464 bytes
99.6%
RT_GROUP_ICON 1 118 bytes
0%
RT_VERSION 1 780 bytes
0.2%
RT_MANIFEST 1 651 bytes
0.2%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The expected hash does not match the digest in SpcInfo

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.00212031 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.00212031 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware