File Name | Adjprog.exe |
File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Scanner Version | 1.0.221.174 |
Database Version | 2025-07-27 20:00:29 UTC |
Malware family: Heuristic
Hash Type | Value | Action |
---|---|---|
MD5 |
6eae297cdceee78bf7e43477736cd939
|
|
SHA1 |
73ae397907afdcad7c84fa59f99b497b556648a7
|
|
SHA256 |
37cf0e974eb8f7520679160d2b9903b0719eb465ddedb41abd10e4f339d709ab
|
|
SHA512 |
2644881ac7898febb238eae70f34484805e2bfc5021101c13d5549a6079a33ffa409c23684a06fa463839c51ced1b9525b0c88b70e318c1d90c3a000170eba93
|
|
ImpHash |
806d0bf83c77663d13165a7cf74a757a
|
Icon |
Hash: 71cebf069993990ed5d14e7ef419091f
Fuzzy: 0e7429eaf47953a7cb95a5ae950d8ead dHash: f8c6ce4666badcf2 |
Image Base | 0x00400000 |
Entry Point | 0x0055f885 |
Compilation Time | 2015-01-28 08:27:22 |
Checksum | 0x00000000 (Actual: 0x0057f905) |
OS Version | 4.0 |
PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
Digital Signature | No valid SignedData structure was found. |
Imports | 12 libraries |
Exports | 0 functions |
Resources | 176 Resources |
Sections | 9 Sections |
FileDescription | Adjustment program for EPSON Inkjet Printer / Scanner |
FileVersion | 1, 0, 0, 0 |
InternalName | AdjProg |
LegalCopyright | Copyright (C) SEIKO EPSON CORPORATION 2002-2007. All rights reserved. |
OriginalFilename | AdjProg.EXE |
ProductName | Adjustment program for EPSON inkjet printer |
ProductVersion | 1, 0, 0, 0 |
Translation | 0x0411 0x04b0 |
Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
---|---|---|---|---|---|---|
.textbss |
0x00001000 |
2,953,216 bytes | 2,949,272 bytes | 5.93 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
A565A32C07D1B289A31BC8511AD796EA |
.text |
0x002d2000 |
8,192 bytes | 8,192 bytes | 4.63 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
B34387A7AD097671932FE024C71C4F3D |
.data |
0x002d4000 |
1,667,072 bytes | 1,667,072 bytes | 7.88 (Packed/Encrypted) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
F81446367FB0D209E7960455AB2234F4 |
.idata |
0x0046b000 |
4,096 bytes | 4,096 bytes | 1.16 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
92A160B6317AA41E0FAC310BE42B6044 |
.rsrc |
0x0046c000 |
16,384 bytes | 16,384 bytes | 3.40 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
B4584FC6210A93F6B782E4BBB8538D31 |
.Silvana |
0x00470000 |
4,096 bytes | 4,096 bytes | 0.44 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
5EACFE37C104B92A7846C66F4883C958 |
.MaThiO |
0x00471000 |
8,646,656 bytes | 4,096 bytes | 1.57 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D78CC83E7EB26C41F2F3FE96A0CB7389 |
ZProtect |
0x00cb0000 |
1,048,576 bytes | 1,048,576 bytes | 4.19 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
C6FBCA10A3EE9CBC26D7A3413C57EE3B |
.mackt |
0x00db0000 |
8,192 bytes | 8,192 bytes | 4.86 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
222F605AB97B06955AF575BC49FF0784 |
1 section(s) with high entropy (≥7.5) detected - possible packing/encryption
Resource Type | Count | Total Size | Percentage |
---|---|---|---|
RT_CURSOR | 16 | 4,800 bytes | |
RT_BITMAP | 2 | 508 bytes | |
RT_ICON | 1 | 3,240 bytes | |
RT_DIALOG | 123 | 110,284 bytes | |
RT_STRING | 14 | 3,718 bytes | |
RT_GROUP_CURSOR | 15 | 314 bytes | |
RT_GROUP_ICON | 1 | 20 bytes | |
RT_VERSION | 1 | 892 bytes | |
RT_MANIFEST | 1 | 86 bytes | |
None | 2 | 38 bytes |
This file is not digitally signed.
⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources
No valid SignedData structure was found.
Recommendation: Verify the file source and ensure it comes from a trusted publisher.
Gridinsoft has the capability to identify and eliminate Trojan.Heur!.03812021 without requiring further user intervention.
Download Anti-MalwareFollow these steps to completely remove the threat from your system