XpsRasteerService.dll threat report

MD5 065bb2ee3fa4e7dbc3da61ed00dc0e3b
Latest seen 2026-03-29 23:01:18 (a month ago)
First seen 2026-03-29 23:01:18 (a month ago)
Size 30 MB

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as General Threat. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
General Threat
Recommended action
Scan and remove
Last analysis
2026-03-29 23:01:18 (a month ago)
File hash
065bb2ee3fa4e7dbc3da61ed00dc0e3b
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as General Threat.

Timeline

First seen 2026-03-29 23:01:18 (a month ago); latest analysis 2026-03-29 23:01:18 (a month ago).

Digital signature

Signed by Shenzhen yundian Technology Co., Ltd. The signature is reported as valid, but signed files can still be bundled or abused.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

XpsRasteerService.dll is a Windows file recorded in the ThreatInfo database. The current detection status is General Threat, based on the latest analysis from 2026-03-29 23:01:18 (a month ago).

If XpsRasteerService.dll appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as General Threat.

MD5: 065bb2ee3fa4e7dbc3da61ed00dc0e3b
Size: 30 MB
First Published: 2026-03-29 23:01:18 (a month ago)
Latest Published: 2026-03-29 23:01:18 (a month ago)
Status: General Threat (on last analysis)
Analysis Date: 2026-03-29 23:01:18 (a month ago)
XpsRasteerService.dll detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

Signed By: Shenzhen yundian Technology Co., Ltd
Status: Valid

The signature on XpsRasteerService.dll is reported as valid. A valid signature helps confirm publisher identity, but it does not automatically make the file safe if the installer was bundled, abused, or downloaded from an untrusted source.

%system%

ThreatInfo has observed XpsRasteerService.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is France with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for XpsRasteerService.dll is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

XpsRasteerService.dll is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000180000000
Entry Address: 0x02e78058

PE Sections:

Name Size of data MD5
45568 af36db1fba5881a95039f3c430ce56ec
18944 194acb481b19df25625c827a4d22fd89
512 ef519b0236104cac8b90b1f2487057d5
3072 6ba583cbda5d9f3e6d9f62cd566a03b4
512 5603a342fba18818bafa5b11fcb515ca
512 48dced7a25617105e4515dc1d6cc7371
1536 bd5d9b43acd429c5b4ed645ee799e157
.edata 512 059e828ae27bdc878ec3a2f5ad309c32
.idata 512 5a2bc5cbea293f4338efbeb902156bc6
.rsrc 512 f3a71ad10502666d97c0a4c957f772e8
.winlice 0 d41d8cd98f00b204e9800998ecf8427e
.boot 31732224 a1d8e3c5bdece9afe12c44688f411eff

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: