| File Name | krnln.fnr |
| File Type |
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
| Scanner Version | 1.0.226.174 |
| Database Version | 2025-10-09 05:00:27 UTC |
Malware family: GenericMC
| Hash Type | Value | Action |
|---|---|---|
| MD5 |
638e737b2293cf7b1f14c0b4fb1f3289
|
|
| SHA1 |
f8e2223348433b992a8c42c4a7a9fb4b5c1158bc
|
|
| SHA256 |
baad4798c3ab24dec8f0ac3cde48e2fee2e2dffa60d2b2497cd295cd6319fd5b
|
|
| SHA512 |
4d714a0980238c49af10376ff26ec9e6415e7057925b32ec1c24780c3671047ac5b5670e46c1c6cf9f160519be8f37e1e57f05c30c6c4bda3b275b143aa0bf12
|
|
| ImpHash |
9724fbe99ea762d6b5643b0bd2357d3f
|
| Icon |
Hash: 757a1ee46490ef1d731f85a5b803649a
Fuzzy: e8d7ded8b3e644bc5b1650bb3b1436cb dHash: a01cc062e4c81368 |
| Image Base | 0x10000000 |
| Entry Point | 0x1009f1b4 |
| Compilation Time | 2009-04-10 02:04:51 |
| Checksum | 0x00000000 (Actual: 0x0010fcb5) |
| OS Version | 4.0 |
| PEiD Signatures |
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
| Digital Signature | No valid SignedData structure was found. |
| Imports | 13 libraries |
| Exports | 2 functions |
| Resources | 92 Resources |
| Sections | 5 Sections |
| CompanyName | |
| FileDescription | |
| FileVersion | 1, 0, 0, 1 |
| InternalName | |
| LegalCopyright | |
| LegalTrademarks | |
| OriginalFilename | |
| ProductName | |
| ProductVersion | 1, 0, 0, 1 |
| Translation | 0x0804 0x04b0 |
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
|---|---|---|---|---|---|---|
.text |
0x00001000 |
792,135 bytes | 794,624 bytes | 6.55 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
7AC046A667BB8F617C0DA9D6E8A85F48 |
.rdata |
0x000c3000 |
109,002 bytes | 110,592 bytes | 4.62 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
E044B5ED2574454040BC6E18640F2C8B |
.data |
0x000de000 |
126,404 bytes | 61,440 bytes | 5.62 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
90B21438B3C6496D224B9D51C64E0E46 |
.rsrc |
0x000fd000 |
58,592 bytes | 61,440 bytes | 4.56 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
C9AE1863AFFDAEE34893094336F66134 |
.reloc |
0x0010c000 |
68,454 bytes | 69,632 bytes | 5.75 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
96AFB1F3AE79A4B15F2DC0998546986B |
1 section(s) with elevated entropy (≥6.5) - possible compression
| Resource Type | Count | Total Size | Percentage |
|---|---|---|---|
| RT_CURSOR | 4 | 1,104 bytes | |
| RT_BITMAP | 56 | 43,248 bytes | |
| RT_ICON | 2 | 1,040 bytes | |
| RT_MENU | 2 | 656 bytes | |
| RT_DIALOG | 11 | 4,756 bytes | |
| RT_STRING | 11 | 2,268 bytes | |
| RT_GROUP_CURSOR | 3 | 74 bytes | |
| RT_GROUP_ICON | 2 | 40 bytes | |
| RT_VERSION | 1 | 588 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
No valid SignedData structure was found.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft has the capability to identify and eliminate Malware.Win32.GenericMC.cc without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system
Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware
Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!