Information about amtlib.dll

amtlib.dll

amtlib.dll is a Windows file recorded in the ThreatInfo database. It is associated with AMTLib (64 Bit). The reported company name is Adobe Systems, Incorporated. The current detection status is Clean, based on the latest analysis from 2022-02-27 23:10:00 (4 years ago).

This record is currently marked as clean, but file reputation can depend on the exact path, hash, and source. Compare the MD5 and publisher data below with the file on your system.

Product Name: AMTLib (64 Bit)
Company Name: Adobe Systems, Incorporated
MD5: 58b02aeb50734509121fffddff29d702
Size: 2 MB
First Published: 2022-02-13 23:26:00 (4 years ago)
Latest Published: 2022-02-27 23:10:00 (4 years ago)
Status: Clean (on last analysis)
Analysis Date: 2022-02-27 23:10:00 (4 years ago)
Signed By: Adobe Systems Incorporated
Status: Trusted Publisher

ThreatInfo marks this publisher as trusted for this record, but the file hash and source should still match the expected software distribution.

%sysdrive%\файлы\adobe photoshop cs6
%programfiles%\photoshop

ThreatInfo has observed amtlib.dll in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Russian Federation with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for amtlib.dll is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

amtlib.dll is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000180000000
Entry Address: 0x0015360c

PE Sections:

Name Size of data MD5
.text 1655808 4e4b0516a9456e81573a6812637db840
.rdata 440320 2bf7c43974f3e610051aa2dcd3bf9726
.data 41984 44e0e56939513adba61c2027e3fdc718
.pdata 90112 7d14867a1889c99ab11dac6d67b304e6
.rsrc 2048 2036c703a3b5d53ffeef9a382d405b8d
.reloc 12288 d19d25f990ea9f3299c6e6e693c87869

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: