Gridinsoft Logo

The amtlib.dll (AMTEmu Licensing) File Analysis

Technical Analysis

File Name amtlib.dll
File Type
Win32 DLL
Magic Bytes PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
SSDEEP Hash
768:DhfOZafnpk/A+scmLaZoKH4d2dtmwIxJXJK0fxlds8PGgtOv896:D5OZafnpUlnoKYd23mlxJXJKcxvHG8Ov
Scanner Version 1.0.178.174
Database Version 2024-06-03 19:00:35 UTC

Suspicious File Detected

Detected by 25 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
34%
Detection Rate
48,640
File Size (bytes)
25/74
Engines Detected
2024-06-03
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
219218ae29b2f9dfc8f6b745c004b1e3
SHA1
8bd073d6ab9e8cc1c973647c769d1597ae3a037b
SHA256
649f3b0148c4f8202b0c2d24a490a99523acc0bd3245c08499162b94ca5d30a5
SHA512
4c9f11752c32153fb936f2ad5f92fedcbd68c9bf2871a0a781d6c5678bfe846dfa99c3364c46a94aeb2d50625d38cd97f395911fd879b319c7222ece00674459
ImpHash
5f931ee6022f63a8566f4e48ef1231f0

Security Engines with Detections (25 of 74)

Lionic
Hacktool.Win32.Crack.3!c Malicious
Elastic
malicious (high confidence) Malicious
Cynet
Malicious (score: 100) Malicious
Cylance
Unsafe Malicious
Zillya
Tool.Crack.Win32.2468 Malicious
K7AntiVirus
Unwanted-Program ( 004d38111 ) Malicious
K7GW
Unwanted-Program ( 004d38111 ) Malicious
Symantec
PUA.Keygen Malicious
ESET-NOD32
Win32/HackTool.Crack.FE potentially unsafe Malicious
Zoner
Trojan.Win32.78207 Malicious
APEX
Malicious Malicious
ClamAV
Win.Malware.Agent-6359986-0 Malicious
McAfeeD
ti!649F3B0148C4 Malicious
Varist
W32/Agent.CNMI-2686 Malicious
Antiy-AVL
Trojan/Win32.BTSGeneric Malicious
Xcitium
ApplicUnsaf@#29x6r89k8hgnd Malicious
Google
Detected Malicious
AhnLab-V3
Unwanted/Win.Crack.C4553834 Malicious
McAfee
GenericRXAA-AA!219218AE29B2 Malicious
Panda
PUP/Patcher Malicious
Yandex
Trojan.Igent.bTuYb1.13 Malicious
Fortinet
Riskware/PUP_XAL Malicious
DeepInstinct
MALICIOUS Malicious
CrowdStrike
win/grayware_confidence_100% (W) Malicious
alibabacloud
Hacktool:Win/Crack Malicious
49 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Image Base 0x10000000
Entry Point 0x10002cb0
Compilation Time 2016-10-20 20:33:12
Checksum 0x00000000 (Actual: 0x0000eac6)
OS Version 6.0
PEiD Signatures PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 5 libraries
SHLWAPI, KERNEL32, USER32, ADVAPI32, SHELL32
Exports 27 functions
Resources 2 Resources
Sections 6 Sections

Version Information

CompanyName painter
FileDescription AMTEmu Licensing
FileVersion 10.0.0.3
InternalName amtlib
LegalCopyright PainteR
OriginalFilename amtlib.dll
ProductName AMTEmu
ProductVersion 10.0.0.3BuildVersion: 10.0; BuildDate: Thu Apr 21 2016 3:6:38)
Translation 0x0419 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 7,367 bytes 7,680 bytes 6.21 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 87B80DAF90487E865EB4582A4F8B4071
.rdata 0x00003000 3,054 bytes 3,072 bytes 5.14 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C09D2B7FB0A2528CD8C32FD0EB9B3EA6
.data 0x00004000 6,884 bytes 5,120 bytes 4.03 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2F04727D00F30D58FF222819E901D728
.pr0 0x00006000 28,695 bytes 29,184 bytes 7.67 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 231BC8B01BDF1AF21B9B70CB1DF5C1FB
.reloc 0x0000e000 888 bytes 1,024 bytes 5.90 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ EBB39D240A07ADC3606CBE420FE04127
.rsrc 0x0000f000 1,313 bytes 1,536 bytes 3.75 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ E06592B84172B8CFC028E1D960EEE5CE
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 2 (1,153 bytes)
Resource Type Count Total Size Percentage
RT_VERSION 1 772 bytes
67%
RT_MANIFEST 1 381 bytes
33%

Certificate Chain Analysis

Certificate Information
Product AMTEmu
Description AMTEmu Licensing
File Version 10.0.0.3
Original Name amtlib.dll
Internal Name amtlib
Copyright PainteR

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
25 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware