REI DS4 NO AUTO PING exe Trojan Heuristic File Malware Analysis: a319ad6c3e2ce030644e2c30bc03f219
Gridinsoft Logo
File Icon

REI DS4 NO AUTO PING.exe Trojan Heuristic Analysis

Technical Analysis

File Name REI DS4 NO AUTO PING.exe
File Type
PE32+ executable (GUI) x86-64, for MS Windows
Scanner Version 1.0.210.174
Database Version 2025-03-14 12:00:53 UTC

Trojan.Heur!.03292423

Malware family: Heuristic

Heuristic detection uses behavioral analysis and pattern recognition to identify potential threats without specific signatures. This proactive approach detects suspicious code behavior that may indicate malware presence. Detection may occasionally produce false positives when legitimate software exhibits similar behavioral patterns.
N/A
Detection Rate
14,460,928
File Size (bytes)
2025-03-14
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
a319ad6c3e2ce030644e2c30bc03f219
SHA1
b969a441e824bade475584f7a947ebec7c9cc7d5
SHA256
b8eb20b5eb9c4851dbbd7989ffae97fc8ef6aa9d82511f67b7f452b8e98b8758
SHA512
59bab9c57f68ab1b34b356802b76949bfc5c8fbb34295206ad3dfbd7203d3060270a13bfd2c0cd2d90e218f952564c2ebcc10be3c508a82d4de9b51400e94350
ImpHash
88f70fb82598484a7ce88eef6418418b

PE Analysis

Basic Information

Icon
Hash: 272db5839c09d43ef0dc4061c95a3475
Fuzzy: d5a81c422894076f0efa8d2949ee5e2f
dHash: 0432b2b270696000
Image Base 0x140000000
Entry Point 0x140eeddf8
Compilation Time 2024-04-16 22:47:28
Checksum 0x00071866 (Actual: 0x00dd6bed)
OS Version 6.0
PEiD Signatures PE32+ executable (GUI) x86-64, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 7 libraries
kernel32, oleaut32, user32, advapi32, ole32, ntdll, shlwapi
Exports 0 functions
Resources 4 Resources
Sections 12 Sections

Version Information

Translation 0x0000 0x04b0
Comments Sony DualShock 4 to Microsoft Xinput controller mapper
CompanyName Ryochan7
FileDescription DS4Windows
FileVersion 3.3.3
InternalName DS4Windows.dll
LegalCopyright Copyright © Scarlet.Crush Productions 2012, 2013; InhexSTER, HecticSeptic, electrobrains 2013, 2014; Jays2Kings 2013, 2014, 2015, 2016; Ryochan7 2017-2023
OriginalFilename DS4Windows.dll
ProductName DS4Windows
ProductVersion 3.3.3+787ac79cc0e394d22ac7c400ba1493c8bb9f40af
Assembly Version 3.3.3.0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 94,208 bytes 40,960 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE CBFB3709E7D24458EC57A876C0E68F70
0x00018000 40,960 bytes 12,288 bytes 7.97 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1E2C7A3086BDB893FB389E5EB75711C1
0x00022000 8,192 bytes 512 bytes 7.03 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 13AC1EE38789BF7B842BD34896F27EE9
0x00024000 8,192 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
0x00026000 4,096 bytes 512 bytes 4.72 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 9A65A28C08898C5E42714BEF4E943F1C
0x00027000 4,096 bytes 1,024 bytes 6.43 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3886A4E2F1FEDB057E0B88F39D7D26E9
0x00028000 278,528 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.rsrc 0x0006c000 278,528 bytes 275,456 bytes 3.07 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE FDA417D25282C59DEF0DACBFBF1C7FEA
0x000b0000 12,005,376 bytes 278,528 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8C12BB48967F8A991533DEEF627CBF76
0x00c23000 2,949,120 bytes 2,947,072 bytes 7.84 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1C0A5842C21F77DFDF2F084F937A2ED6
.enigma1 0x00ef3000 4,096 bytes 10,010,624 bytes 7.90 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 7EC3344E68A2F5786E177BFBA1BB442B
.enigma2 0x00ef4000 892,928 bytes 892,928 bytes 5.73 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 3FEF55E1B2DCF53F589F002882B90779
Entropy Analysis Alert

5 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 4 (274,766 bytes)
Resource Type Count Total Size Percentage
RT_ICON 1 270,376 bytes
98.4%
RT_GROUP_ICON 1 20 bytes
0%
RT_VERSION 1 1,244 bytes
0.5%
RT_MANIFEST 1 3,126 bytes
1.1%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Trojan.Heur!.03292423 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.03292423 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware