Gridinsoft Logo
File Icon

The ezCheckPrinting(activated)[1].exe File Analysis

Technical Analysis

File Name ezCheckPrinting(activated)[1].exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
196608:5vUM86wV+Aeps2oA4APwvHpsIh3p2Z8AZw5lSExL7:5v186S7eps2oALPuJP3xAG7
Scanner Version 1.0.211.174
Database Version 2025-03-21 17:00:40 UTC

Suspicious File Detected

Detected by 28 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
39%
Detection Rate
6,761,984
File Size (bytes)
28/72
Engines Detected
2025-03-21
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
3aa71c2ab5858e186e537670ee5585b6
SHA1
1fbbd57b2a27c3bebab5448fa728a95228edf2e2
SHA256
9c953445d882e92aaa24d9141e85b8b68b4a005fcef9f7d647dbf4807b12f50e
SHA512
6c1d96eba9d1433ea79ec35a5747ce61df9c34c009aea8965491a03f630f2adae4e8a3e0fdebaebc86749e4168f1da3101972c36482d64ea2728235087d5dd1a
ImpHash
3c029866402cd0e87160c4e37f17636e

Security Engines with Detections (28 of 72)

Bkav
W32.AIDetectMalware Malicious
Elastic
malicious (high confidence) Malicious
Skyhigh
Artemis!Trojan Malicious
McAfee
Artemis!3AA71C2AB585 Malicious
Cylance
Unsafe Malicious
CrowdStrike
win/malicious_confidence_60% (D) Malicious
VirIT
Trojan.Win32.GenHeur.C Malicious
ESET-NOD32
a variant of Win32/Spy.LummaStealer.T Malicious
APEX
Malicious Malicious
Avast
Win32:SpywareX-gen [Trj] Malicious
Kaspersky
UDS:DangerousObject.Multi.Generic Malicious
Rising
Spyware.LummaStealer!8.1A464 (TFE:5:qpXfqpzBxHG) Malicious
F-Secure
Trojan.TR/Dropper.Gen Malicious
SentinelOne
Static AI - Malicious PE Malicious
Trapmine
malicious.high.ml.score Malicious
Sophos
Generic ML PUA (PUA) Malicious
FireEye
Generic.mg.3aa71c2ab5858e18 Malicious
Avira
TR/Dropper.Gen Malicious
Antiy-AVL
Trojan/Win32.Caynamer Malicious
Microsoft
Trojan:Win32/Sabsik.FL.A!ml Malicious
Cynet
Malicious (score: 99) Malicious
AhnLab-V3
Malware/Win.Generic.C5742248 Malicious
VBA32
BScope.TrojanRansom.Stealc Malicious
Malwarebytes
Spyware.Lumma Malicious
TrendMicro-HouseCall
Trojan.Win32.VSX.PE04C9V Malicious
huorong
HVM:VirTool/Obfuscator.gen!A Malicious
AVG
Win32:SpywareX-gen [Trj] Malicious
DeepInstinct
MALICIOUS Malicious
44 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 461f849288228b8ab2975ea84213580c
Fuzzy: 5b45e36b5fa610cae402370f764e8121
dHash: 71e4c4d4d4dcd871
Image Base 0x00400000
Entry Point 0x00401be0
Compilation Time 2025-03-20 23:14:00
Checksum 0x0067e4bc (Actual: 0x0067e4bc)
OS Version 6.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature No valid SignedData structure was found.
Imports 3 libraries
KERNEL32, USER32, ADVAPI32
Exports 0 functions
Resources 34 Resources
Sections 5 Sections

Version Information

Comments The recipe suggestion feature has transformed my cooking experience
CompanyName DataPioneers Technologies.
FileDescription I love how it integrates with my email to streamline my workflow
FileVersion 5.3.52.287
InternalName TaskEaseApp
LegalCopyright Copyright (C) 2024-2025 by DataPioneers Technologies.
OriginalFilename AtomRPG.exe
ProductName Task Manager DeLuxe
ProductVersion 5.3.52.287
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 3,389 bytes 3,584 bytes 5.97 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ C7942EE14531F8A6CDF4BCAA5E6C676D
.rdata 0x00002000 3,799 bytes 4,096 bytes 4.44 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 279E09BCB5022B21C577FE379C3386AB
.data 0x00003000 365,008 bytes 365,056 bytes 8.00 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE E4BB2547038AD799ADB708130F4A024D
.rsrc 0x0005d000 6,387,689 bytes 6,387,712 bytes 7.98 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 5AF241A003F597308FDAEBF25AA55793
.reloc 0x00675000 408 bytes 512 bytes 5.51 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 56379BA1983D10BCD46319B94687B56E
Entropy Analysis Alert

2 section(s) with high entropy (≥7.5) detected - possible packing/encryption

Resource Analysis

Total Resources: 34 (6,385,794 bytes)
Resource Type Count Total Size Percentage
RT_ICON 10 232,253 bytes
3.6%
RT_MENU 7 4,844 bytes
0.1%
RT_DIALOG 4 1,254 bytes
0%
RT_STRING 5 1,640 bytes
0%
RT_ACCELERATOR 4 184 bytes
0%
RT_RCDATA 1 6,144,000 bytes
96.2%
RT_GROUP_ICON 1 146 bytes
0%
RT_VERSION 1 1,092 bytes
0%
RT_MANIFEST 1 381 bytes
0%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
28 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware