The file is safe to use. The trust index of this analysis is 55 % (moderate).



atieclxx.exe is a ATI Controlpanel. It is part of the application ATi Graphiccard drivers, developed by AMD. This file is responsible for a hardware piece in your system. It offers additional configuration options and support for this device

Threat analysis: Safe
Analysis trust:
Recent activity:
First seen: 19 May, 2015
Last seen: 03 Aug, 2019
Last analysis: 28 Aug, 2019
Possible infection: Clean

Signature verification


This file has no digital signature. The publisher of this file could not be verified.

Product AMD External Events
Description AMD External Events Client Module
File entropy

File entropy match: Random data

The file contains random data or highly encrypted data. This might have been done to avoid detection.

| 0 b.776192 b. |
Plain Data Text Code Compressed Encrypted Random

File signature

Executable file

An executable file causes a computer "to perform indicated tasks according to encoded instructions," as opposed to a data file that must be parsed by a program to be meaningful.

The determination of a file type is done with a signature or magic-numbers. Files are identified using by comparing the first set of bytes in the file header. Using this method type of files are recognised no matter the extension used. This information is useful to for example recognise executable files cloaked as images or movies.


Malicious code scan

No malicious code found

Agics makes een analysis of the source code of the file. We look for comparisons with known malicious source code. This is a good way to detect new malicious files which are in fact variations of existing, and known malicious files.

Scan results:

0 %

Fuzzy hash a.k.a. Context Triggered Piecewise Hashing


Context Triggered Piecewise Hashing, also called Fuzzy Hashing, can match inputs that have homologies. Such inputs have sequences of identical bytes in the same order, although bytes in between these sequences may be different in both content and length. Comparing a fuzzyhash is a good way to detect morphing malware. Malware which include random code in every copy to change its properties. Agics uses ssdeep to make create a fuzzyhash.

SSDEEP: 12288:HEkwa92bAc07dD6HIMZwbB2Cg8/CBeK6FlwMgBTm4OUBBO7LJSLq:HmE65KdD8ZwVsxEJU1QZqO7lSe

No match found


Online virus scanners

Detection ration:

0 %

Not available on is a repository of malware samples to provide security researchers, incident responders, forensic analysts, and the morbidly curious access to samples of live malicious code. Presence of the sample on this site indicates that the file is (Once considered) being malicious.

National Software Reference Library

Not on the nsrl list

The NSRL contains a collection of digital signatures of known, traceable software applications. There are application hash values in the hash set which may be considered malicious, i.e. steganography tools and hacking scripts.



Sandbox behaviour analysis:

The file is executed in a safe environment to track its behaviour. The behaviour analysis can help with detecting new malware which is not recognized by virusscanners yet. However it has a high chance on a false-positive, especially with installers, uninstallers and virusscanners.

Network activity

No internet connection

Dropped files

File name md5


Import hashing

Imphash 771683b3f94c2113cbb57040127d503d

Fingerprinting files can be done in various way. One way is to make a hash of the PE Imports. PE Imports are relative unique and this is a great way to find new variants of existing malware. The chance of false-positives is relative high. The resulting hash is often called an imphash.

0% Match0% Match

Statistic analysis

Statistic analysis of the file

Deviates from other files with the same name (imitation)
No certificate
Other files with the same name do not have a certificate as well
This is a very common file

Neural network analysis

Analysis: Low risk

A neural network is a type of artificial intelligence. It recognized patterns nog clear for a human viewer. Our neural network is surprisingly accurate in recognizing dangerous files. The value below is the predicted chance the file is malicious.

10%10 %


