Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5, 4, 6, 3 33.33%
5, 1, 4, 2 33.33%
4, 2, 7, 2 33.33%

Relationships

Parent process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
SetSecurityDescriptorDacl, AllocateAndInitializeSid, SetEntriesInAclA, SetNamedSecurityInfoA, FreeSid, LookupPrivilegeValueA, AdjustTokenPrivileges, StartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerA, ControlService, DeleteService, SetServiceStatus, OpenThreadToken, OpenProcessToken, RegEnumKeyExA, CreateServiceA, ChangeServiceConfig2A, GetTokenInformation, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, IsValidSid, GetLengthSid, CopySid, RegQueryInfoKeyA, RegSetValueExA, RegQueryValueExA, RegOpenKeyExA, RegCreateKeyExA, RegCloseKey, RegDeleteValueA, RegDeleteKeyA, OpenSCManagerA, OpenServiceA, CloseServiceHandle
comdlg32.dll
GetFileTitleA
dnssd.dll
DNSServiceRefSockFD, DNSServiceProcessResult, DNSServiceRegister, DNSServiceQueryRecord, DNSServiceResolve, DNSServiceBrowse, DNSServiceRefDeallocate
gdi32.dll
OffsetViewportOrgEx, SetViewportOrgEx, SelectObject, Escape, ExtTextOutA, GetStockObject, CreateBitmap, DeleteDC, ScaleWindowExtEx, SetWindowExtEx, ScaleViewportExtEx, GetClipBox, SetMapMode, SetTextColor, GetDeviceCaps, SaveDC, RestoreDC, SetBkColor, TextOutA, RectVisible, PtVisible, DeleteObject, SetViewportExtEx
kernel32.dll
GetFileAttributesA, GetFileTime, GetLocaleInfoA, GetCPInfo, GetOEMCP, RtlUnwind, HeapFree, VirtualProtect, VirtualAlloc, GetSystemInfo, VirtualQuery, HeapReAlloc, ExitProcess, TerminateProcess, UnhandledExceptionFilter, IsDebuggerPresent, GetSystemTimeAsFileTime, GetTimeFormatA, GetDateFormatA, GetStartupInfoA, HeapSize, GetACP, IsValidCodePage, VirtualFree, HeapDestroy, HeapCreate, GetStdHandle, GetTimeZoneInformation, LCMapStringA, LCMapStringW, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetConsoleCP, GetConsoleMode, GetStringTypeA, GetStringTypeW, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetEnvironmentVariableA, FileTimeToLocalFileTime, GlobalFlags, FileTimeToSystemTime, lstrcmpA, TlsFree, LocalReAlloc, TlsSetValue, TlsAlloc, GlobalHandle, GlobalReAlloc, TlsGetValue, LocalAlloc, GlobalGetAtomNameA, GlobalAddAtomA, GlobalFindAtomA, GlobalDeleteAtom, lstrcmpW, GetVersionExA, GetFullPathNameA, GetVolumeInformationA, DuplicateHandle, GetFileSize, SetEndOfFile, FlushFileBuffers, SetFilePointer, ReadFile, LoadLibraryA, GetThreadLocale, GetProcAddress, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, WriteFile, LockFile, UnlockFile, GetComputerNameA, EnterCriticalSection, LeaveCriticalSection, WTSGetActiveConsoleSessionId, CreateEventA, WaitForMultipleObjects, ResetEvent, SetEvent, FindFirstFileA, FindClose, WaitForSingleObject, GetExitCodeThread, CompareStringW, CompareStringA, GetVersion, InterlockedExchange, UnmapViewOfFile, CreateFileMappingA, MapViewOfFile, CreateMutexA, ReleaseMutex, MoveFileA, GetTickCount, GetCurrentProcessId, SetLastError, CreateDirectoryA, CreateFileA, LocalFree, GetCommandLineA, GetCurrentThreadId, CreateThread, Sleep, DeleteFileA, GetModuleHandleA, LoadLibraryExA, FreeLibrary, IsDBCSLeadByte, GetCurrentThread, GetCurrentProcess, CloseHandle, GetModuleFileNameA, lstrcmpiA, InterlockedIncrement, GetLastError, FindResourceA, LoadResource, LockResource, SizeofResource, DeleteCriticalSection, InitializeCriticalSection, RaiseException, lstrlenW, WideCharToMultiByte, MultiByteToWideChar, InterlockedDecrement, FormatMessageA, lstrlenA, GetProcessHeap, HeapAlloc, SetUnhandledExceptionFilter
ole32.dll
OleRun, CoCreateInstance, CLSIDFromProgID, CLSIDFromString, CoUninitialize, CoInitializeEx, CoTaskMemAlloc, CoTaskMemRealloc, CoRevokeClassObject, CoRegisterClassObject, CoTaskMemFree, CoInitialize, StringFromGUID2, CoInitializeSecurity
psapi.dll
EnumProcesses
shell32.dll
SHGetSpecialFolderPathA
shlwapi.dll
PathStripToRootA, PathIsUNCA, PathFindFileNameA
user32.dll
LoadBitmapA, ModifyMenuA, EnableMenuItem, CheckMenuItem, UnregisterClassA, GetSysColorBrush, ValidateRect, RegisterWindowMessageA, WinHelpA, GetCapture, SetWindowsHookExA, CallNextHookEx, GetClassLongA, GetClassNameA, SetPropA, GetPropA, RemovePropA, GetForegroundWindow, GetTopWindow, GetMessageTime, GetMessagePos, MapWindowPoints, GetKeyState, SetForegroundWindow, GetClientRect, GetMenu, GetClassInfoExA, GetClassInfoA, RegisterClassA, AdjustWindowRectEx, CopyRect, PtInRect, CallWindowProcA, GetMenuCheckMarkDimensions, GetWindowPlacement, GetWindowRect, GetWindowTextLengthA, GetWindowTextA, GetFocus, SetWindowLongA, GetDlgCtrlID, GetDlgItem, GetWindow, GetSystemMetrics, GetWindowThreadProcessId, GetParent, GetWindowLongA, GetLastActivePopup, IsWindowEnabled, EnableWindow, GetSysColor, ReleaseDC, ClientToScreen, GrayStringA, DrawTextExA, DrawTextA, TabbedTextOutA, UnhookWindowsHookEx, GetMenuState, GetMenuItemID, GetMenuItemCount, GetSubMenu, KillTimer, DefWindowProcA, DestroyWindow, SystemParametersInfoA, SetWindowPos, SetMenuItemBitmaps, DestroyMenu, IsIconic, CharUpperA, wsprintfA, PeekMessageA, PostQuitMessage, GetDC, SetWindowTextA, TranslateMessage, MessageBoxA, LoadIconA, LoadCursorA, RegisterClassExA, CreateWindowExA, SetTimer, GetMessageA, DispatchMessageA, PostMessageA, SendMessageA, PostThreadMessageA, LoadStringA, CharNextA, IsWindow
version.dll
GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
winspool.drv
DocumentPropertiesA, OpenPrinterA, ClosePrinter
wtsapi32.dll
WTSRegisterSessionNotification, WTSFreeMemory, WTSQuerySessionInformationA, WTSUnRegisterSessionNotification

EKDiscovery.exe

EKDiscovery Module by Eastman Kodak Company (Signed)

Remove EKDiscovery.exe
Version:   4, 2, 7, 2
MD5:   10c0f6417eccbee2b74301ece9a0efbe
SHA1:   008075dbcf0e22b645d5ce43a023d36391fb971d
SHA256:   d6c1b3f4a968e38da4d3cf46fdb4c92e15092d6c4768ca5c3e00dbe33603d2b7

Overview

ekdiscovery.exe runs as a service under the name Kodak AiO Network Discovery Service with extensive SYSTEM privileges (full administrator access). It is installed with a couple of know programs including KODAK AiO Home Center published by Eastman Kodak Company, KODAK Home Center Software from Eastman Kodak Company and KODAK Home Center Software by Eastman Kodak Company. The file is digitally signed by Eastman Kodak Company which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:ekdiscovery.exe
Publisher:Eastman Kodak Company
Product name:EKDiscovery Module
Description:EKDiscovery Module for Kodak AiO Printers
Typical file path:C:\Program Files\kodak\aio\center\ekdiscovery.exe
File version:4, 2, 7, 2
Size:277.36 KB (284,016 bytes)
Build date:7/24/2009 3:11 PM
Certificate
Issued to:Eastman Kodak Company
Authority (CA):VeriSign
Effective date:Wednesday, August 13, 2008
Expiration date:Friday, September 3, 2010
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Eastman Kodak Company
20% remove
With this version of software, you can easily download PrintProjects software, which helps you design, print, and share photo cards, calendars, books, and more. With PrintProjects software, you can print at home or have your creations shipped to you. This software uses code of FFmpeg licensed under the LGPLv2.1.
Eastman Kodak Company
3% remove
KODAK Home Center Software is installed as part of the software installation on your computer. The Home Center icon will appear on your desktop. Use this icon to start Home Center Software. On a WINDOWS OS-based computer, you can use Home Center Software to browse and edit pictures, print, copy, scan, order supplies, access the Extended User Guide, and configure your all-in-one printer from your computer. You can also access the KODAK T...
Eastman Kodak Company
12% remove
With this version of software, you can easily download PrintProjects software, which helps you design, print, and share photo cards, calendars, books, and more. With PrintProjects software, you can print at home or have your creations shipped to you. This software uses code of FFmpeg licensed under the LGPLv2.1.
Eastman Kodak Company
27% remove
With this version of software, you can easily download PrintProjects software, which helps you design, print, and share photo cards, calendars, books, and more. With PrintProjects software, you can print at home or have your creations shipped to you.
Eastman Kodak Company
12% remove
On a WINDOWS OS-based computer, you can use Home Center Software to browse and edit pictures, print, copy, scan, order supplies, access the Extended User Guide, and configure your all-in-one printer from your computer. You can also access the KODAK Tips and Projects Center Web site or upgrade your printer with a newer version of software and/or firmware. KODAK Home Center Software is installed as part of the software installation on yo...

BehaviorsBehaviors

Service
Runs under 'SYSTEM\CurrentControlSet\Services' by the Service Controller (services.exe)
  • 'Kodak AiO Network Discovery Service'

ResourcesResource utilization

(Note: statistics below are averages based on a minimum sample size of 200 unique participants)
Averages
 
CPU
Total CPU:0.00031779%
0.028634%
Kernel CPU:0.00014835%
0.013761%
User CPU:0.00016944%
0.014873%
Kernel CPU time:218 ms/min
100,923,805ms/min
CPU cycles:36,787/sec
17,470,203/sec
Memory
Private memory:18.85 MB
21.59 MB
Private (maximum):18.83 MB
Private (minimum):308 KB
Non-paged memory:18.85 MB
21.59 MB
Virtual memory:164.02 MB
140.96 MB
Virtual memory (peak):169.02 MB
169.69 MB
Working set:9.54 MB
18.61 MB
Working set (peak):18.84 MB
37.95 MB
Page faults:10,498/min
2,039/min
I/O
I/O read transfer:240 Bytes/sec
1.02 MB/min
I/O read operations:1/sec
343/min
I/O write transfer:20 Bytes/sec
274.99 KB/min
I/O write operations:1/sec
227/min
I/O other transfer:528 Bytes/sec
448.09 KB/min
I/O other operations:12/sec
1,671/min
Resource allocations
Threads:9
12
Handles:332
600

BehaviorsProcess properties

Integrety level:System
Platform:64-bit
Command line:C:\aio\center\ekdiscovery.exe
Owner:SYSTEM
Windows Service
Service name:Kodak AiO Network Discovery Service
Type:Win32OwnProcess
Parent process:services.exe (Services and Controller app by Microsoft)

ResourcesThreads

Averages
 
wow64.dll (Win32 Emulation on NT64 by Microsoft)
Total CPU:0.00059391%
0.272967%
Kernel CPU:0.00042422%
0.107585%
User CPU:0.00016969%
0.165382%
CPU cycles:15,300/sec
5,741,424/sec
Memory:252 KB
1.16 MB
ekdiscovery.exe (main module)
Total CPU:0.00004244%
Kernel CPU:0.00000000%
User CPU:0.00004244%
CPU cycles:554/sec
Memory:288 KB

Common loaded modules

These are modules that are typiclaly loaded within the context of this process.

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 33.33%
Microsoft Windows XP 33.33%
Windows Vista Home Premium 33.33%

Distribution by countryDistribution by country

United States installs about 100.00% of EKDiscovery Module.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Toshiba 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE