| File Name | MBSetup.exe |
| File Type |
PE32 executable (GUI) Intel 80386, for MS Windows
|
| Scanner Version | 1.0.227.174 |
| Database Version | 2025-10-10 13:00:15 UTC |
No threats detected by our scanner
| Hash Type | Value | Action |
|---|---|---|
| MD5 |
edcbb964b10523dea5c6a9616f17cd5b
|
|
| SHA1 |
7752c05c20ef8bb8f9f522fae17bfab57c82bae3
|
|
| SHA256 |
2913073395c78cbc67d2c6c8c191c71a7ada50aabf12e8315d6126d8fa9538d2
|
|
| SHA512 |
5024aa53068763416b240e75d0dc0f50ade67fe9de8dd535e73506655e73a8432ec8842664d3ba45b92422eb9f144ce4a3faf95e4e92b7509bae3a5fee7f48c5
|
|
| ImpHash |
d3c026afe97504ed51e97e42c40d0c29
|
| Icon |
Hash: c811b162b64291b6dca0621d5667fec6
Fuzzy: 7a3f04e0588d6a4d10b233fb88a3e1b1 dHash: 68aab2aaccccf030 |
| Image Base | 0x00400000 |
| Entry Point | 0x0045c11b |
| Compilation Time | 2022-12-06 00:23:21 |
| Checksum | 0x0027287a (Actual: 0x0027287a) |
| OS Version | 6.0 |
| PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
| PDB Path | d:\jenkins\workspace\A_MB4_MBSetup\bin\Win32\Release\MBSetup.pdb |
| Digital Signature | OK |
| Imports |
3 libraries
KERNEL32, CRYPT32, RPCRT4 |
| Exports | 0 functions |
| Resources | 315 Resources |
| Sections | 5 Sections |
| CompanyName | Malwarebytes |
| FileDescription | Malwarebytes Setup |
| FileVersion | 4.5.19.299 |
| LegalCopyright | Copyright (C) 2017 - 2021 Malwarebytes, Inc. All rights reserved. |
| InternalName | MBSetup.exe |
| OriginalFilename | MBSetup.exe |
| ProductName | Malwarebytes |
| Translation | 0x0409 0x04b0 |
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
|---|---|---|---|---|---|---|
.text |
0x00001000 |
650,104 bytes | 650,240 bytes | 6.58 (Compressed) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
8D7164913ED2F5A9E26ECECBBDF755B7 |
.rdata |
0x000a0000 |
164,088 bytes | 164,352 bytes | 5.06 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
027546A8B11581DD084E5C3DD66D2953 |
.data |
0x000c9000 |
22,492 bytes | 16,896 bytes | 4.64 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
04860BE299E3D2A2D001003354A8AFD6 |
.rsrc |
0x000cf000 |
1,599,656 bytes | 1,600,000 bytes | 6.90 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
7DB61FDF1B3FD11CB7B1C406CD21D0B4 |
.reloc |
0x00256000 |
38,580 bytes | 38,912 bytes | 6.67 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
591ED7438C875C9DF862FD61FEC8AFE3 |
3 section(s) with elevated entropy (≥6.5) - possible compression
| Resource Type | Count | Total Size | Percentage |
|---|---|---|---|
| BINARY | 2 | 335,596 bytes | |
| PNG | 64 | 574,082 bytes | |
| RESOURCEFILE | 2 | 123,218 bytes | |
| RT_BITMAP | 4 | 97,876 bytes | |
| RT_ICON | 6 | 116,841 bytes | |
| RT_DIALOG | 9 | 5,210 bytes | |
| RT_STRING | 225 | 332,754 bytes | |
| RT_GROUP_ICON | 1 | 90 bytes | |
| RT_VERSION | 1 | 764 bytes | |
| RT_MANIFEST | 1 | 2,082 bytes |
| Product | Malwarebytes |
| Description | Malwarebytes Setup |
| File Version | 4.5.19.299 |
| Original Name | MBSetup.exe |
| Signing Date | 12:27 AM 12/06/2022 (1130 days ago) |
| Verification Status | Signed |
| Signers | Malwarebytes Inc.; Sectigo RSA Code Signing CA 2; USERTrust RSA Certification Authority; Sectigo (AAA) |
| Counter Signers | Microsoft Public RSA Time Stamping Authority; Microsoft Public RSA Timestamping CA 2020; Microsoft Identity Verification Root Certificate Authority 2020 |
| Internal Name | MBSetup.exe |
| Copyright | Copyright (C) 2017 - 2021 Malwarebytes, Inc. All rights reserved. |
39 72 44 3A F9 22 B7 51 D7 D3 6C 10 DD 31 35 95A6 57 F7 78 B3 1A E5 23 D6 67 13 17 18 D1 6E B29E 02 B0 E9 4A CE B2 10 9C A1 E9 83 6B E0 C2 DB33 00 00 00 05 E5 CF 0F FF 66 2E C9 87 00 00 00 00 00 0533 00 00 00 1D AE C9 44 A1 CE 22 00 AB 00 00 00 00 00 1D54 98 D2 D1 D4 5B 19 95 48 13 79 C8 11 C0 87 9933 00 00 4C 88 DF 71 3F D6 E8 75 41 A3 00 00 00 00 4C 8833 00 00 00 07 37 8C 5B A1 D9 5B 8C D4 00 00 00 00 00 0733 00 00 00 07 87 A3 34 A3 7B A5 8E 1C 00 00 00 00 00 0733 00 00 00 1E 13 57 DA 40 37 CD FC 82 00 00 00 00 00 1E✓ This file has been digitally signed and the certificate chain has been verified
OK
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-MalwareThis file appears clean, but regular security maintenance is important
Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware
Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!