Gridinsoft Logo
File Icon

The prototypef.exe (Prototype) File Analysis

Technical Analysis

File Name prototypef.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
12288:yJpnpnpnpnpaB/B/B/B/B0MnshGzN+358fBSZyxeD0TAS:yyB/B/B/B/B1cGEJdZyxeD0TV
Scanner Version 1.0.215.174
Database Version 2025-04-27 15:00:23 UTC

Suspicious File Detected

Detected by 7 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
10%
Detection Rate
2,617,344
File Size (bytes)
7/73
Engines Detected
2025-04-27
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
6e782bf7a3d0dc0aef0cf7de9a383c4f
SHA1
c4235736f2b41adbe3dd0aa0efc9aeb02db8c10a
SHA256
ceb61bb153f12fe2117d4f35c900d02a5127e68a0c3f79a3a3ba195718560892
SHA512
c7789cf0bffc700c8f199fad6feb4498a3d615daa0bbcc5b8b82d1648f7c348c951d2bad941783310db85da3fb3dd291975a772d3ad5bbde238cd8eaacd1319a
ImpHash
24fe5756987c16e1f7011d0af53662a0

Security Engines with Detections (7 of 73)

Symantec
ML.Attribute.HighConfidence Malicious
tehtris
Generic.Malware Malicious
APEX
Malicious Malicious
Paloalto
generic.ml Malicious
McAfeeD
ti!CEB61BB153F1 Malicious
Kingsoft
malware.kb.a.920 Malicious
Cynet
Malicious (score: 100) Malicious
66 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: bf507cd79a7bc09e481d7701c224fd0f
Fuzzy: 12a3105c55ffac64e96c42ba7887c150
dHash: 0111717949697133
Image Base 0x00400000
Entry Point 0x004023f4
Compilation Time 2009-04-22 12:03:58
Checksum 0x00287a37 (Actual: 0x00287a37)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path d:\worker1\prototype\playable\win32\prototypef.pdb
Digital Signature No valid SignedData structure was found.
Imports 6 libraries
KERNEL32, USER32, GDI32, ole32, OLEAUT32, MSVCR80
Exports 0 functions
Resources 79 Resources
Sections 5 Sections

Version Information

Comments http://www.prototypegame.com
CompanyName Activision
FileDescription Prototype
FileVersion 1,0,0,1
InternalName PrototypePC
LegalCopyright Copyright (C) 2008
OriginalFilename Prototype.exe
ProductName Prototype
ProductVersion 1,0,0,1
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 6,780 bytes 8,192 bytes 6.47 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 1281BE5AA0D483E55D4CBEFB60D8F4AA
.rdata 0x00003000 5,124 bytes 8,192 bytes 3.83 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E1D0C9F56FF4E27E8D0EED9D978CA01A
.data 0x00005000 1,028 bytes 4,096 bytes 0.20 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 6D6650CE93AF25464DBC0669639CA100
.rsrc 0x00006000 2,239,120 bytes 2,240,512 bytes 3.29 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 866568E5D1CCE2A017C7B5BE4395B1D5
.666 0x00229000 352,256 bytes 352,256 bytes 7.98 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ BF22B4B9200122E00834512843801628
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 79 (2,235,346 bytes)
Resource Type Count Total Size Percentage
DATA 10 173,328 bytes
7.8%
RT_CURSOR 1 3,244 bytes
0.1%
RT_ICON 60 2,056,480 bytes
92%
RT_GROUP_CURSOR 1 20 bytes
0%
RT_GROUP_ICON 5 870 bytes
0%
RT_VERSION 1 772 bytes
0%
RT_MANIFEST 1 632 bytes
0%

Certificate Chain Analysis

Certificate Information
Product Prototype
Description Prototype
File Version 1,0,0,1
Original Name Prototype.exe
Internal Name PrototypePC
Copyright Copyright (C) 2008

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
7 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware