Gridinsoft Logo

The dowser.exe File Analysis

Technical Analysis

File Name dowser.exe
File Type
PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Scanner Version 1.0.229.174
Database Version 2025-11-18 21:00:21 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
7,565,376
File Size (bytes)
2025-11-18
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
991a80b0498d32758ba627e71e4d70fa
SHA1
9852005cda2b4ca958d29425a54185e8c60995d8
SHA256
6d477f1bd0813ce0f89a140783d3c2e6f22b3123a9da184a605269050c578793
SHA512
089733136afc76651646990a623f58733982535c7986bec3d8b0d55d71a7238406ef164af2b69c12acf83a60879eebfd4d41f75b5a889528ebeaca6de480e15e
ImpHash
9cbefe68f395e67356e2a5d8d1b285c0

PE Analysis

Basic Information

Image Base 0x00400000
Entry Point 0x004666c0
Compilation Time 1970-01-01 00:00:00
Checksum 0x0073c327 (Actual: 0x0073c327)
OS Version 6.1
PEiD Signatures PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
Digital Signature OK
Imports 1 libraries
kernel32
Exports 0 functions
Resources 0 Resources
Sections 13 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 2,556,091 bytes 2,556,416 bytes 6.15 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D25F69CE6E4766EEEF69AD1840B74D7D
.rdata 0x00272000 2,428,000 bytes 2,428,416 bytes 5.66 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 6D6999E611D318A90D5252B0439EC1D7
.data 0x004c3000 641,672 bytes 250,368 bytes 5.30 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 4B2326137CD2E38BE1132A8D9779A8EB
/4 0x00560000 295 bytes 512 bytes 5.10 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES 43DC7A0AE5A7067502907DB800396667
/19 0x00561000 422,238 bytes 422,400 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES 29AB4C08D82F1D7DCCFEE659977E8865
/32 0x005c9000 84,548 bytes 84,992 bytes 7.94 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES 1A15DF502835D1603609B3B02720BE8E
/46 0x005de000 48 bytes 512 bytes 0.86 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES 40CCA7C46FC713B4F088E5D440CA7931
/65 0x005df000 699,402 bytes 699,904 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES 23E8128474C80E4C3EEA93F2D8D5E641
/78 0x0068a000 574,576 bytes 574,976 bytes 7.99 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES 75B644D1CD401B536ADA19C8D4AC1D87
/90 0x00717000 142,819 bytes 142,848 bytes 7.81 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ|IMAGE_SCN_ALIGN_1BYTES 292BA1EFC5E503394889D9890FFB7A4E
.idata 0x0073a000 1,148 bytes 1,536 bytes 3.53 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE F3CD9D0FA81440B8DE4AACF37807F662
.reloc 0x0073b000 42,052 bytes 42,496 bytes 5.43 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 4163DC1B5B68909C5273C82A27BCCC26
.symtab 0x00746000 348,042 bytes 348,160 bytes 5.36 (Normal) IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 708029A684430390F4F8DEB7ECDEDD6B
Entropy Analysis Alert

5 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Certificate Chain Analysis

Certificate Information
Signing Date 10:54 AM 02/11/2025 (332 days ago)
Verification Status Signed
Signers Paradox Interactive AB (publ); DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4; DigiCert
Counter Signers DigiCert Timestamp 2024; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Certificate Chain Summary
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #1 Primary
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
Paradox Interactive AB (publ) #2 Chain
Validity Period: 2024-12-16 00:00:00 → 2025-12-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0C 1C BB AD DB 20 AD 34 11 AD 96 D3 65 62 24 3D
DigiCert Timestamp 2024 #3 Chain
Validity Period: 2024-09-26 00:00:00 → 2035-11-25 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0B AE 66 BC 5A BA 7F 95 87 C6 F9 E9 04 E3 33 04
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #4 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted Root G4 #5 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Your Score for
/

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware