Gridinsoft Logo
File Icon

The ExtPassword.exe (ExtPassword!) File Analysis

Technical Analysis

File Name ExtPassword.exe
File Type
Win32 EXE
Magic Bytes PE32 executable (GUI) Intel 80386, for MS Windows
SSDEEP Hash
6144:/zpZOJ8y/uyULU8PHShgDCO0rH3PkNSSHPx9j/gojzrx5nxE4dvr:/zpQJ8ymyUo8SgDkD/kNV5/gobRvr
Scanner Version 1.0.178.174
Database Version 2024-06-07 14:00:44 UTC

Suspicious File Detected

Detected by 35 security engines - requires caution

This file requires additional checking for potential threats. Based on suspicious indicators, we will soon add it to our virus database.
49%
Detection Rate
372,736
File Size (bytes)
35/72
Engines Detected
2024-06-07
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
2e477a549f15fcb4ae26f4206b5bfebc
SHA1
f479b5859833b19aa4f5354ff0243ac91fb77a5d
SHA256
bd7734a4d8403353e875efbb1d5f3b1a636eda8b83f6884f3b011157ca419df5
SHA512
ea931f747fb14d8a22f039cc07b1509dade45a951d6958dc3255b0671313a6df04ee9ff8cfa76a79f7b44114f31c8e19f3872b071abcec16cc5212e764e85d0a
ImpHash
0c6ab8386a0a5a3a34c44da535416997

Security Engines with Detections (35 of 72)

Bkav
W32.AIDetectMalware Malicious
Lionic
Trojan.Win32.Generic.4!c Malicious
MicroWorld-eScan
Gen:Variant.Application.Nirsoft.249993 Malicious
FireEye
Gen:Variant.Application.Nirsoft.249993 Malicious
Skyhigh
RDN/Generic PUP.z Malicious
ALYac
Gen:Variant.Application.Nirsoft.249993 Malicious
Cylance
Unsafe Malicious
K7AntiVirus
Riskware ( 00584baa1 ) Malicious
Alibaba
Trojan:Win32/Generic.5253053e Malicious
K7GW
Riskware ( 00584baa1 ) Malicious
Cybereason
malicious.49f15f Malicious
BitDefenderTheta
Gen:NN.ZexaCO.36806.wq0@aOiYGtdO Malicious
Symantec
ML.Attribute.HighConfidence Malicious
APEX
Malicious Malicious
TrendMicro-HouseCall
HackTool.Win32.NirPassExt.A Malicious
BitDefender
Gen:Variant.Application.Nirsoft.249993 Malicious
Avast
Win32:Malware-gen Malicious
Emsisoft
Gen:Variant.Application.Nirsoft.249993 (B) Malicious
VIPRE
Gen:Variant.Application.Nirsoft.249993 Malicious
TrendMicro
HackTool.Win32.NirPassExt.A Malicious
McAfeeD
ti!BD7734A4D840 Malicious
Sophos
NirPassView (PUA) Malicious
Webroot
W32.Adware.Gen Malicious
Antiy-AVL
Trojan/Win32.SGeneric Malicious
Kingsoft
malware.kb.a.826 Malicious
Microsoft
Trojan:Win32/Zpevdo.B Malicious
Xcitium
Malware@#82fsot4j6egi Malicious
Arcabit
Trojan.Application.Nirsoft.D3D089 Malicious
GData
Gen:Variant.Application.Nirsoft.249993 Malicious
McAfee
RDN/Generic PUP.z Malicious
MAX
malware (ai score=77) Malicious
Malwarebytes
Generic.Malware.AI.DDS Malicious
MaxSecure
Trojan.Malware.118910950.susgen Malicious
AVG
Win32:Malware-gen Malicious
DeepInstinct
MALICIOUS Malicious
37 engines reported no threats - Only engines with detections are shown above for clarity

PE Analysis

Basic Information

Icon
Hash: 3f3c684a4d72db97832c66787566ab61
Fuzzy: 53c583c9ce8b61dd41c7edd07bb1d6e9
dHash: 0000300279f8e4d4
Image Base 0x00400000
Entry Point 0x004493e0
Compilation Time 2019-08-20 15:01:29
Checksum 0x000681fd (Actual: 0x000681fd)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path c:\Projects\VS2005\ExtPassword\Release\ExtPassword.pdb
Digital Signature The PE file does not contain a certificate table.
Imports 8 libraries
msvcrt, COMCTL32, VERSION, KERNEL32, USER32, GDI32, comdlg32, SHELL32
Exports 0 functions
Resources 37 Resources
Sections 4 Sections

Version Information

CompanyName NirSoft
FileDescription ExtPassword!
FileVersion 0.90
InternalName ExtPassword!
LegalCopyright Copyright © 2019 Nir Sofer
OriginalFilename ExtPassword.exe
ProductName ExtPassword!
ProductVersion 0.90
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 298,375 bytes 298,496 bytes 6.64 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 642C0FB0FF6132CAA43E08BCC8CBC738
.rdata 0x0004a000 43,024 bytes 43,520 bytes 5.58 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 321DC0EBD8A84E75BEDD376338B3A10D
.data 0x00055000 15,796 bytes 6,656 bytes 3.23 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE B883695B50147407324F680C71F214CC
.rsrc 0x00059000 22,612 bytes 23,040 bytes 4.22 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4E27C6C9AD13F4379179B9711AC7B381
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 37 (20,523 bytes)
Resource Type Count Total Size Percentage
RT_CURSOR 1 308 bytes
1.5%
RT_BITMAP 3 5,848 bytes
28.5%
RT_ICON 3 5,688 bytes
27.7%
RT_MENU 3 1,516 bytes
7.4%
RT_DIALOG 6 2,820 bytes
13.7%
RT_STRING 15 2,376 bytes
11.6%
RT_ACCELERATOR 1 88 bytes
0.4%
RT_GROUP_CURSOR 1 20 bytes
0.1%
RT_GROUP_ICON 2 54 bytes
0.3%
RT_VERSION 1 712 bytes
3.5%
RT_MANIFEST 1 1,093 bytes
5.3%

Certificate Chain Analysis

Certificate Information
Product ExtPassword!
Description ExtPassword!
File Version 0.90
Original Name ExtPassword.exe
Internal Name ExtPassword!
Copyright Copyright © 2019 Nir Sofer

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
35 antivirus engines detected potential threats. This could be a false positive, especially for system tools or packed software. Verify the file source and check if it's digitally signed by a trusted publisher.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware