Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5, 4, 6, 3 33.33%
5, 1, 4, 2 33.33%
4, 2, 7, 2 33.33%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
SetSecurityDescriptorDacl, AllocateAndInitializeSid, SetEntriesInAclA, SetNamedSecurityInfoA, FreeSid, LookupPrivilegeValueA, AdjustTokenPrivileges, StartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerA, ControlService, DeleteService, SetServiceStatus, OpenThreadToken, OpenProcessToken, RegEnumKeyExA, CreateServiceA, ChangeServiceConfig2A, GetTokenInformation, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, IsValidSid, GetLengthSid, CopySid, RegQueryInfoKeyA, RegSetValueExA, RegQueryValueExA, RegOpenKeyExA, RegCreateKeyExA, RegCloseKey, RegDeleteValueA, RegDeleteKeyA, OpenSCManagerA, OpenServiceA, CloseServiceHandle
comdlg32.dll
GetFileTitleA
dnssd.dll
DNSServiceRefSockFD, DNSServiceProcessResult, DNSServiceRegister, DNSServiceQueryRecord, DNSServiceResolve, DNSServiceBrowse, DNSServiceRefDeallocate
gdi32.dll
OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, ExtTextOutA, GetStockObject, CreateBitmap, DeleteDC, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, GetClipBox, SetMapMode, SetTextColor, GetDeviceCaps, SaveDC, RestoreDC, SetBkColor, TextOutA, RectVisible, PtVisible, DeleteObject, SetViewportExtEx
kernel32.dll
GetFileAttributesA, GetFileTime, GetLocaleInfoA, GetCPInfo, GetOEMCP, RtlUnwind, HeapFree, VirtualProtect, VirtualAlloc, GetSystemInfo, VirtualQuery, HeapReAlloc, ExitProcess, TerminateProcess, UnhandledExceptionFilter, IsDebuggerPresent, GetSystemTimeAsFileTime, GetTimeFormatA, GetDateFormatA, GetStartupInfoA, HeapSize, GetACP, IsValidCodePage, VirtualFree, HeapDestroy, HeapCreate, GetStdHandle, GetTimeZoneInformation, LCMapStringA, LCMapStringW, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetConsoleCP, GetConsoleMode, GetStringTypeA, GetStringTypeW, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetEnvironmentVariableA, FileTimeToLocalFileTime, GlobalFlags, FileTimeToSystemTime, lstrcmpA, TlsFree, LocalReAlloc, TlsSetValue, TlsAlloc, GlobalHandle, GlobalReAlloc, TlsGetValue, LocalAlloc, GlobalGetAtomNameA, GlobalAddAtomA, GlobalFindAtomA, GlobalDeleteAtom, lstrcmpW, GetVersionExA, GetFullPathNameA, GetVolumeInformationA, DuplicateHandle, GetFileSize, SetEndOfFile, FlushFileBuffers, SetFilePointer, ReadFile, LoadLibraryA, GetThreadLocale, GetProcAddress, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, WriteFile, LockFile, UnlockFile, GetComputerNameA, EnterCriticalSection, LeaveCriticalSection, WTSGetActiveConsoleSessionId, CreateEventA, WaitForMultipleObjects, ResetEvent, SetEvent, FindFirstFileA, FindClose, WaitForSingleObject, GetExitCodeThread, CompareStringW, CompareStringA, GetVersion, InterlockedExchange, UnmapViewOfFile, CreateFileMappingA, MapViewOfFile, CreateMutexA, ReleaseMutex, MoveFileA, GetTickCount, GetCurrentProcessId, SetLastError, CreateDirectoryA, CreateFileA, LocalFree, GetCommandLineA, GetCurrentThreadId, CreateThread, Sleep, DeleteFileA, GetModuleHandleA, LoadLibraryExA, FreeLibrary, IsDBCSLeadByte, GetCurrentThread, GetCurrentProcess, CloseHandle, GetModuleFileNameA, lstrcmpiA, InterlockedIncrement, GetLastError, FindResourceA, LoadResource, LockResource, SizeofResource, DeleteCriticalSection, InitializeCriticalSection, RaiseException, lstrlenW, WideCharToMultiByte, MultiByteToWideChar, InterlockedDecrement, FormatMessageA, lstrlenA, GetProcessHeap, HeapAlloc, SetUnhandledExceptionFilter
ole32.dll
OleRun, CoCreateInstance, CLSIDFromProgID, CLSIDFromString, CoUninitialize, CoInitializeEx, CoTaskMemAlloc, CoTaskMemRealloc, CoRevokeClassObject, CoRegisterClassObject, CoTaskMemFree, CoInitialize, StringFromGUID2, CoInitializeSecurity
psapi.dll
EnumProcesses
shell32.dll
SHGetSpecialFolderPathA
shlwapi.dll
PathStripToRootA, PathIsUNCA, PathFindFileNameA
user32.dll
LoadBitmapA, ModifyMenuA, EnableMenuItem, CheckMenuItem, UnregisterClassA, GetSysColorBrush, ValidateRect, RegisterWindowMessageA, WinHelpA, GetCapture, SetWindowsHookExA, CallNextHookEx, GetClassLongA, GetClassNameA, SetPropA, GetPropA, RemovePropA, GetForegroundWindow, GetTopWindow, GetMessageTime, GetMessagePos, MapWindowPoints, GetKeyState, SetForegroundWindow, GetClientRect, GetMenu, GetClassInfoExA, GetClassInfoA, RegisterClassA, AdjustWindowRectEx, CopyRect, PtInRect, CallWindowProcA, GetMenuCheckMarkDimensions, GetWindowPlacement, GetWindowRect, GetWindowTextLengthA, GetWindowTextA, GetFocus, SetWindowLongA, GetDlgCtrlID, GetDlgItem, GetWindow, GetSystemMetrics, GetWindowThreadProcessId, GetParent, GetWindowLongA, GetLastActivePopup, IsWindowEnabled, EnableWindow, GetSysColor, ReleaseDC, ClientToScreen, GrayStringA, DrawTextExA, DrawTextA, TabbedTextOutA, UnhookWindowsHookEx, GetMenuState, GetMenuItemID, GetMenuItemCount, GetSubMenu, KillTimer, DefWindowProcA, DestroyWindow, SystemParametersInfoA, SetWindowPos, SetMenuItemBitmaps, DestroyMenu, IsIconic, CharUpperA, wsprintfA, PeekMessageA, PostQuitMessage, GetDC, SetWindowTextA, TranslateMessage, MessageBoxA, LoadIconA, LoadCursorA, RegisterClassExA, CreateWindowExA, SetTimer, GetMessageA, DispatchMessageA, PostMessageA, SendMessageA, PostThreadMessageA, LoadStringA, CharNextA, IsWindow
version.dll
GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
winspool.drv
DocumentPropertiesA, OpenPrinterA, ClosePrinter
wtsapi32.dll
WTSRegisterSessionNotification, WTSFreeMemory, WTSQuerySessionInformationA, WTSUnRegisterSessionNotification

EKDiscovery.exe

EKDiscovery Module by Eastman Kodak Company (Signed)

Remove EKDiscovery.exe
Version:   5, 4, 6, 3
MD5:   1a8d8cb042e2724385227f1a19a8decc
SHA1:   45a996f54d5c218debf24c2d208e1fd88b749a46
SHA256:   362f8779d4f5e4fc8437dfb908f2da26d6d99074ede41756f95cf8b48a38b1ab

Overview

ekdiscovery.exe runs as a service under the name Kodak AiO Network Discovery Service with extensive SYSTEM privileges (full administrator access). It is installed with a couple of know programs including KODAK AiO Home Center published by Eastman Kodak Company, KODAK AiO Home Centre from Eastman Kodak Company and KODAK AiO Home Centre by Eastman Kodak Company. The file is digitally signed by Eastman Kodak Company which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:ekdiscovery.exe
Publisher:Eastman Kodak Company
Product name:EKDiscovery Module
Description:EKDiscovery Module for Kodak AiO Printers
Typical file path:C:\Program Files\kodak\aio\center\ekdiscovery.exe
File version:5, 4, 6, 3
Size:301.42 KB (308,656 bytes)
Certificate
Issued to:Eastman Kodak Company
Authority (CA):VeriSign
Effective date:Wednesday, August 13, 2008
Expiration date:Friday, September 3, 2010
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Eastman Kodak Company
20% remove
With this version of software, you can easily download PrintProjects software, which helps you design, print, and share photo cards, calendars, books, and more. With PrintProjects software, you can print at home or have your creations shipped to you. This software uses code of FFmpeg licensed under the LGPLv2.1.
Eastman Kodak Company
12% remove
With this version of software, you can easily download PrintProjects software, which helps you design, print, and share photo cards, calendars, books, and more. With PrintProjects software, you can print at home or have your creations shipped to you. This software uses code of FFmpeg licensed under the LGPLv2.1.
Eastman Kodak Company
3% remove
KODAK Home Center Software is installed as part of the software installation on your computer. The Home Center icon will appear on your desktop. Use this icon to start Home Center Software. On a WINDOWS OS-based computer, you can use Home Center Software to browse and edit pictures, print, copy, scan, order supplies, access the Extended User Guide, and configure your all-in-one printer from your computer. You can also access the KODAK T...
Eastman Kodak Company
27% remove
With this version of software, you can easily download PrintProjects software, which helps you design, print, and share photo cards, calendars, books, and more. With PrintProjects software, you can print at home or have your creations shipped to you.
Eastman Kodak Company
7% remove
With this software, you can set up your classic (non-cloud ready) printer to enable cloud printing, which allows you to print from anywhere with your smartphone, tablet, or computer.
Eastman Kodak Company
10% remove
This is the software driver and additional utilities required for managing and connecting the KODAK All-in-One Printer Software device to the PC. Uninstalling this driver may cause the hardware to stop functioning properly (only remove this package if you no longer have the device connected to your PC).

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'Kodak AiO Network Discovery Service'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00041105%
0.028634%
Kernel CPU:0.00033632%
0.013761%
User CPU:0.00007474%
0.014873%
Kernel CPU time:702 ms/min
100,923,805ms/min
CPU cycles:48,854/sec
17,470,203/sec
Memory
Private memory:24.64 MB
21.59 MB
Private (maximum):22.21 MB
Private (minimum):836 KB
Non-paged memory:24.64 MB
21.59 MB
Virtual memory:180.82 MB
140.96 MB
Virtual memory (peak):198.92 MB
169.69 MB
Working set:2.18 MB
18.61 MB
Working set (peak):24.69 MB
37.95 MB
Page faults:17,998/min
2,039/min
I/O
I/O read transfer:311 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:15 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:1.39 KB/sec
448.09 KB/min
I/O other operations:20/sec
1,671/min
Resource allocations
Threads:11
12
Handles:453
600

BehaviorsProcess properties

Integrety level:System
Platform:32-bit
Command line:"C:\Program Files\kodak\aio\center\ekdiscovery.exe"
Owner:SYSTEM
Windows Service
Service name:Kodak AiO Network Discovery Service
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
ADVAPI32.dll
Total CPU:0.00116552%
0.272967%
Kernel CPU:0.00092644%
0.107585%
User CPU:0.00023908%
0.165382%
CPU cycles:30,529/sec
5,741,424/sec
Memory:792 KB
1.16 MB
ekdiscovery.exe (main module)
Total CPU:0.00017930%
Kernel CPU:0.00014941%
User CPU:0.00002988%
CPU cycles:3,638/sec
Memory:312 KB
mscorwks.dll
Total CPU:0.00007482%
Kernel CPU:0.00007482%
User CPU:0.00000000%
CPU cycles:928/sec
Memory:5.66 MB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 33.33%
Microsoft Windows XP 33.33%
Windows Vista Home Premium 33.33%

Distribution by countryDistribution by country

United States installs about 100.00% of EKDiscovery Module.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE