Gridinsoft Logo
File Icon

The EzUpdt.exe File Analysis

Technical Analysis

File Name EzUpdt.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.210.174
Database Version 2025-03-08 21:00:37 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
1,466,816
File Size (bytes)
2025-03-08
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
5f1e4618c6cddf47199aa832412ec561
SHA1
4c732d0114bba2497f55b4dcd0d8e69f72a1e1ba
SHA256
679464a7ebb57c3ed67574d67b52a4847b635813958302c88ee8f766c682fecc
SHA512
aa014fd45f27f25acd164de650ce204dbc0aeade61fd1b5082ed081040829cd87bb24769778cb63e8cd32999eb20790ecf9e3e804b5983ef8a425928290ecc94
ImpHash
d59dadc58ef1add58a7b05fee5322a3c

PE Analysis

Basic Information

Icon
Hash: 015819d3237163fff48c477363846f65
Fuzzy: 0d60f6ca10b3924b7e826a049532b358
dHash: 70d8dcd8c0e47080
Image Base 0x00400000
Entry Point 0x004014d0
Compilation Time 2018-10-18 07:32:15
Checksum 0x00170f93 (Actual: 0x00170f93)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature OK
Imports 11 libraries
Exports 298 functions
Resources 43 Resources
Sections 8 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 806,912 bytes 803,328 bytes 6.49 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 4A8D6A55206DBAE0E2E83142FA67E672
.data 0x000c6000 151,552 bytes 109,056 bytes 4.60 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2A5F11DD0B4D20E86AF1974A0FBFB84C
.tls 0x000eb000 4,096 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rdata 0x000ec000 4,096 bytes 512 bytes 0.21 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ 74DB701125A7B2FF0A014C4400295279
.idata 0x000ed000 16,384 bytes 12,800 bytes 5.19 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B3DC93E5FA5E47550AA785F75A50FDEA
.edata 0x000f1000 16,384 bytes 15,872 bytes 5.68 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 7A3F05938041E7C46B2EFD06AA10DB8F
.rsrc 0x000f5000 466,944 bytes 465,408 bytes 3.98 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 19AC2248F5323113BE865F56EF62101E
.reloc 0x00167000 53,248 bytes 51,712 bytes 6.62 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_SHARED|IMAGE_SCN_MEM_READ 30ACD4066EDEBB008982E128C0B7F956
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 43 (462,644 bytes)
Resource Type Count Total Size Percentage
RT_CURSOR 7 2,156 bytes
0.5%
RT_ICON 7 408,024 bytes
88.2%
RT_STRING 16 15,308 bytes
3.3%
RT_RCDATA 5 36,912 bytes
8%
RT_GROUP_CURSOR 7 140 bytes
0%
RT_GROUP_ICON 1 104 bytes
0%

Certificate Chain Analysis

Certificate Information
Signing Date 07:32 AM 10/18/2018 (2424 days ago)
Verification Status A certificate was explicitly revoked by its issuer.
Signers ASUSTeK Computer Inc.; DigiCert SHA2 Assured ID Code Signing CA; DigiCert
Counter Signers Symantec Time Stamping Services Signer - G4; Symantec Time Stamping Services CA - G2; Thawte Timestamping CA
Certificate Chain Summary
Symantec Time Stamping Services CA - G2 #1 Primary
Validity Period: 2012-12-21 00:00:00 → 2020-12-30 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 7E 93 EB FB 7C C6 4E 59 EA 4B 9A 77 D4 06 FC 3B
Symantec Time Stamping Services Signer - G4 #2 Chain
Validity Period: 2012-10-18 00:00:00 → 2020-12-29 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 0E CF F4 38 C8 FE BF 35 6E 04 D8 6A 98 1B 1A 50
DigiCert SHA2 Assured ID Code Signing CA #3 Chain
Validity Period: 2013-10-22 12:00:00 → 2028-10-22 12:00:00
Signature Algorithm: sha256RSA
Serial Number: 04 09 18 1B 5F D5 BB 66 75 53 43 B5 6F 95 50 08
ASUSTeK Computer Inc. #4 Chain
Validity Period: 2018-06-20 00:00:00 → 2021-06-22 12:00:00
Signature Algorithm: sha256RSA
Serial Number: 05 E6 A0 BE 5A C3 59 C7 FF 11 F4 B4 67 AB 20 FC

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware