Gridinsoft Logo

The DUI.dll File Analysis

Technical Analysis

File Name DUI.dll
File Type
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.211.174
Database Version 2025-03-28 23:01:27 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
1,310,208
File Size (bytes)
2025-03-28
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
56c69f405987fe2fe08bd09b58d4204f
SHA1
f29add1c732c1682a469fa7cfce7c212eef78df9
SHA256
fe37094e371a9e9a36b04ea0f19457f9b88a0032eebe73f1353e5a353c50e0fb
SHA512
efdf181c80fb556ec562b5a57a25b7fc50399a4beef948348ffe0179494433007cc8fe53d3ab453f1ce977313ceb0c90344c8e11d5a901689ce1c3ccd0960239
ImpHash
0480a453323100a002f26bebb4a83460

PE Analysis

Basic Information

Image Base 0x10000000
Entry Point 0x1008589c
Compilation Time 2024-12-01 10:19:44
Checksum 0x00000000 (Actual: 0x0014fb47)
OS Version 6.0
PEiD Signatures PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
PDB Path D:\work\workspace\zcsk-code\DarmosharkMouse-X6Realtek\bin\DUI.pdb
Digital Signature No valid SignedData structure was found.
Imports 20 libraries
Exports 2168 functions
Resources 6 Resources
Sections 7 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 574,558 bytes 574,976 bytes 6.18 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 27CF4248E16D74993A848793D3B6AAB9
.rdata 0x0008e000 213,486 bytes 213,504 bytes 5.97 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 86CA59F636584A4A05D6E410883E3CC9
.data 0x000c3000 4,828 bytes 3,584 bytes 4.63 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 9F99A6B5FEA9C5F87450D23C451978DC
.gfids 0x000c5000 84 bytes 512 bytes 0.41 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C2D5FC2262934A27A9CF6FADC2E93AB4
.tls 0x000c6000 9 bytes 512 bytes 0.02 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 1F354D76203061BFDD5A53DAE48D5435
.rsrc 0x000c7000 483,112 bytes 483,328 bytes 6.68 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ C0B4CF0CA688B457527F18D2F597EE3A
.reloc 0x0013d000 32,484 bytes 32,768 bytes 6.64 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 441BF1C73AA69533803E38E70190D035
Entropy Analysis Alert

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 6 (482,695 bytes)
Resource Type Count Total Size Percentage
PNG 2 1,175 bytes
0.2%
TTF 3 480,880 bytes
99.6%
RT_MANIFEST 1 640 bytes
0.1%

Certificate Chain Analysis

Certificate Information
Certificate Chain Summary
VeriSign Time Stamping Services Signer - G2 #1 Primary
Validity Period: 2007-06-15 00:00:00 → 2012-06-14 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 38 25 D7 FA F8 61 AF 9E F4 90 E7 26 B5 D6 5A D5
VeriSign Time Stamping Services CA #2 Chain
Validity Period: 2003-12-04 00:00:00 → 2013-12-03 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 47 BF 19 95 DF 8D 52 46 43 F7 DB 6D 48 0D 31 A4
VeriSign Class 3 Code Signing 2009-2 CA #3 Chain
Validity Period: 2009-05-21 00:00:00 → 2019-05-20 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 65 52 26 E1 B2 2E 18 E1 59 0F 29 85 AC 22 E7 5C
Monotype Imaging Inc. #4 Chain
Validity Period: 2010-07-29 00:00:00 → 2012-08-08 23:59:59
Signature Algorithm: sha1RSA
Serial Number: 66 E3 F0 67 79 CA 15 16 6D 50 53 6F 88 19 1A 83

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

No valid SignedData structure was found.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware