The "Heur" stands for "heuristic," which means we use a set of rules, algorithms, or behavioral analysis to detect potential threats that may not have a specific, known signature. It's a proactive approach to identifying suspicious behavior or code patterns that could indicate the presence of a Trojan or other malware. The file's behavior or characteristics triggered the heuristic analysis as potentially malicious. However, it doesn't necessarily confirm that the file is indeed a Trojan. It could be a false positive, where a legitimate program exhibits behavior that resembles malicious activity.

Checked:2023-09-22 15:15:17
File Size:9080320 bytes

Trojan.Heur!.02052023 Removal

Gridinsoft has the capability to identify and eliminate Trojan.Heur!.02052023 without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

FileDescriptionPaleoScan - A Breakthrough in Seismic Interpretation
LegalCopyrightCopyright © 2017
Translation0x0409 0x04b0

Portable Executable Info

Image Base:0x140000000
Entry Point:0x1401dd794
Compilation:2023-08-01 07:36:05
Checksum:0x00000000 (Actual: 0x008ad52e)
OS Version:6.0
PDB Path:E:\Jenkins\workspace\8.1_PS_Release_master\paleoscanproduct\bin\ps_ow_connect.pdb
PEiD:PE32+ executable (GUI) x86-64, for MS Windows
Sign:The PE file does not contain a certificate table.
Imports: owdevkit11_10, LGCbase11_10, LGCsdl11_10, propertybrowserLib, mdprocess, faultsLib, eventbuslib, api-ms-win-crt-runtime-l1-1-0, api-ms-win-crt-convert-l1-1-0, api-ms-win-crt-stdio-l1-1-0, api-ms-win-crt-string-l1-1-0, api-ms-win-crt-math-l1-1-0, api-ms-win-crt-environment-l1-1-0, api-ms-win-crt-filesystem-l1-1-0, api-ms-win-crt-utility-l1-1-0, api-ms-win-crt-heap-l1-1-0, VCRUNTIME140, VCRUNTIME140_1, SHELL32, NETAPI32, COMCTL32, WSOCK32, ole32, SHLWAPI, KERNEL32, USER32, COMDLG32, ADVAPI32, OLEAUT32, GLU32, OPENGL32, Qt5Widgets, Qt5Gui, Qt5Xml, Qt5Sql, Qt5Network, Qt5Concurrent, Qt5Core, eliis, psWidgets, MSVCP140, VCOMP140, WS2_32, gdal300, proj_6_2, api-ms-win-crt-time-l1-1-0, api-ms-win-crt-locale-l1-1-0, dhcpcsvc, WINTRUST, CRYPT32,
Exports: 52


Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x00209fe7 0x0020a000 e45df97b17d88901f19017e9a04eeb3d 6.42
.textidx 0x0020b000 0x000949b5 0x00094a00 6f3cd906cda2f359b5cf2bb01aec87fd 6.10
.rdata 0x002a0000 0x005b431c 0x005b4400 5a27d019e9ddf5ecd13f3aa4607d85a3 7.27
.data 0x00855000 0x000192b8 0x00011c00 28ec4329f8823530ca5e6095aa578af5 4.47
.pdata 0x0086f000 0x0001ae14 0x0001b000 ef349428da6d215cb0a7f195443a275a 6.21
.fnp_dir 0x0088a000 0x00000078 0x00000200 38af43d61a4127d1eea12b4ae15c6786 0.90
.fnp_mar 0x0088b000 0x00000001 0x00000200 bf619eac0cdf3f68d496ea9344137e8b 0.00
.rsrc 0x0088c000 0x00023088 0x00023200 b7726c47e8b22321b9d758004d5690cd 7.19
.reloc 0x008b0000 0x00005a00 0x00005a00 e0c49ba81007463d9d0ea3ba41bd3a18 5.46

