Gridinsoft Logo
File Icon

The kaspersky4win202121.21.7.384ar_en_46680.exe File Analysis

Technical Analysis

File Name kaspersky4win202121.21.7.384ar_en_46680.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.215.174
Database Version 2025-05-02 03:00:29 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
5,178,088
File Size (bytes)
2025-05-02
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
a86559ac9b6e4315d9dd46b7e2ba45b6
SHA1
2c4a902abdee484302e0f11cea6b66b516d56ff3
SHA256
11963b5bb64019c343589e8a9d9ff9d760bf8b48a0b2a6b5ed3d60dfdeb8fdba
SHA512
958297d6bbfd17a26d0a90633fdc6ab7c01460b4347e54c0241730b93184873f3fee570f7bf05f087ddd627803c02e96c62a57af8c27f57433d67a4c469eb765
ImpHash
3b629027afbe60960e4099d322d33917

PE Analysis

Basic Information

Icon
Hash: ef82e732356f511d4f52114a73b46a32
Fuzzy: 3b4b79729883f89ca608d3c14f8141a0
dHash: 70e0f8fc9c9af870
Image Base 0x00400000
Entry Point 0x00403b10
Compilation Time 2025-04-16 07:20:24
Checksum 0x004fe43e (Actual: 0x004f40e9)
OS Version 6.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path C:\a\b\d_00000000_\b\b\execroot\k\bazel-out\x86_32-windows-opt-ST-bd47c771e5d9\bin\product\kavkis\PPP\Install\Setup\starter\setup.pdb
Digital Signature OK
Imports 1 libraries
KERNEL32
Exports 0 functions
Resources 36 Resources
Sections 6 Sections

Version Information

CompanyName Kaspersky
FileDescription Kaspersky [21.21.7.384.0.22.0]
FileVersion 21.21.7.384
LegalCopyright ‎© 2025 AO Kaspersky Lab‎
LegalTrademarks العلامات التجارية المسجلة وعلامات الخدمة مملوكة لأصحابها.
ProductName Kaspersky
ProductVersion 21.21.7.384
InternalName Setup
OriginalFilename Setup.exe
Translation 0x0409 0x04b0
CompanyName Kaspersky
FileDescription Kaspersky [21.21.7.384.0.22.0]
FileVersion 21.21.7.384
LegalCopyright © 2025 AO Kaspersky Lab
LegalTrademarks Registered trademarks and service marks are the property of their respective owners
ProductName Kaspersky
ProductVersion 21.21.7.384
InternalName Setup
OriginalFilename Setup.exe
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 255,226 bytes 255,488 bytes 6.65 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 590C7FB1723291D38341B4EF93A8BCAA
.rdata 0x00040000 76,096 bytes 76,288 bytes 5.34 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ AA0410CB43AC71844A64CA36EEA15392
.data 0x00053000 19,748 bytes 5,120 bytes 3.39 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 75C87EEA48D8BE875090BBD2B940182F
.didat 0x00058000 64 bytes 512 bytes 0.58 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE A307096FE46992D5C228DEC3101EB6E2
.rsrc 0x00059000 4,810,720 bytes 4,810,752 bytes 7.89 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 3DA27C1ECCCB0EB3B800BE882DA390B3
.reloc 0x004f0000 12,716 bytes 12,800 bytes 6.64 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 5A19E78CA21E55B439A08316B946F3B9
Entropy Analysis Alert

1 section(s) with high entropy (≥7.5) detected - possible packing/encryption

2 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 36 (4,807,677 bytes)
Resource Type Count Total Size Percentage
DOWNLOADER.INI 2 586 bytes
0%
DYN_CUST_DATA 1 1,543 bytes
0%
SZIP 19 4,428,962 bytes
92.1%
WEVT_TEMPLATE 1 498 bytes
0%
RT_ICON 7 372,408 bytes
7.7%
RT_STRING 1 38 bytes
0%
RT_MESSAGETABLE 1 100 bytes
0%
RT_GROUP_ICON 1 104 bytes
0%
RT_VERSION 2 1,832 bytes
0%
RT_MANIFEST 1 1,606 bytes
0%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware