Gridinsoft Logo

The util64.exe File Analysis

Technical Analysis

File Name util64.exe
File Type
PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Scanner Version 1.0.247.174
Database Version 2026-06-04 17:00:36 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
31,920
File Size (bytes)
2026-06-04
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
c2a7f19ba96dc460d591d37d664fe6aa
SHA1
2e930eb7072ac6f8906c5df11e041d88aaea1fcd
SHA256
7ad4b911d05a12f91ab27ba3baa351a56653ca099dda7ad87ee2b94f8cd018c9
SHA512
baf23c903b68e13786657cf1bcfc6db55493988eac28edc3caaee1011f65ff04eebef9e204853a3abf07d4a36ad7ef5bb8a3683863fac600b49590d7376624ad
ImpHash
5bbfcbabfc013bccac23927b24324ffd

PE Analysis

Basic Information

Image Base 0x140000000
Entry Point 0x140001440
Compilation Time 2026-04-01 04:24:07
Checksum 0x0000b2ff (Actual: 0x0000b2ff)
OS Version 4.0
PEiD Signatures PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 3 libraries
KERNEL32, msvcrt, lua51
Exports 0 functions
Resources 1 Resources
Sections 10 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 13,088 bytes 13,312 bytes 5.89 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ CBCD3ED99E35D1BD69D6AA64A9E583B3
.data 0x00005000 224 bytes 512 bytes 0.92 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 137E515D7F087785A874034414B9877A
.rdata 0x00006000 4,736 bytes 5,120 bytes 4.97 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 833AD5DE66A6AE54E8C33397AB117B9F
.pdata 0x00008000 816 bytes 1,024 bytes 3.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 35ABA10D535749B3857CD1ED6C19AFA9
.xdata 0x00009000 652 bytes 1,024 bytes 2.83 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ B38016F2F71C51E527485E4172AE5F9E
.bss 0x0000a000 480 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_UNINITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.idata 0x0000b000 3,512 bytes 3,584 bytes 3.96 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 72617636AA82E9F758ED6E6ED4A534B3
.tls 0x0000c000 16 bytes 512 bytes 0.00 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BF619EAC0CDF3F68D496EA9344137E8B
.rsrc 0x0000d000 1,256 bytes 1,536 bytes 4.78 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 68A1F44719FFEBA49B98199EB2B39412
.reloc 0x0000e000 124 bytes 512 bytes 1.53 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ FF01E22AC1B36C9EF0A126DDE1BC75E6

Resource Analysis

Total Resources: 1 (1,167 bytes)
Resource Type Count Total Size Percentage
RT_MANIFEST 1 1,167 bytes
100%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. 1
    Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
  2. 2
    Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
  3. 3
    Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
  4. 4
    Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Proactive Protection
This file looks clean right now, but that doesn't mean you should let your guard down. New malware appears daily, and even legit files can be compromised after download. When in doubt, verify the source and check for a digital signature.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.

Gridinsoft Portal
Signed in via Gridinsoft Portal · View profile
Your Score for

Gridinsoft Anti-Malware

Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware

Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!

Gridinsoft Anti-Malware