The Setup.exe (Outbyte Driver Updater Installation File) File Analysis
Technical Analysis
| File Name | Setup.exe |
| File Type |
Win32 EXE
|
| Magic Bytes | PE32 executable (GUI) Intel 80386, for MS Windows |
| SSDEEP Hash |
393216:mN2NlreCD2m/MnaaMw2SvNfS0xY2/OCvhW1SItsQe29E9GXrFdSLWIy:m430mEa855SSYD/1SI2Qe2CcTbIy
|
| Scanner Version | 1.0.251.174 |
| Database Version | 2026-08-03 02:00:16 UTC |
Suspicious File Detected
Detected by 4 security engines - requires caution
Scan Another File
File Identification
| Hash Type | Value | Action |
|---|---|---|
| MD5 |
220837c2f22829c288e2585a9e625ae2
|
|
| SHA1 |
9cca1b4ea934836a2d5b51189c52462d98647eef
|
|
| SHA256 |
6d05134b2789f9eb04d368cef3b525c0fd04802662a30e855fe9d7ae87eabd3e
|
|
| SHA512 |
d8338c6094ed5f45c86f17a13b0fd3dc56f3bbe9f5845cd7c785e1410901f5cce91ff14f9f4539888a04024a243c73117d9db8e2fb7f62a9a788d7f4870d4598
|
|
| ImpHash |
4d65eb009a5bed7efce0091931f34eb4
|
Security Engines with Detections (4 of 71)
PE Analysis
Basic Information
▼| Icon |
Hash: 7c1dfc962f1a439ad168791f64aad960
Fuzzy: e43b0d2a5676919fbc4b132c9047bc5b dHash: c8c0a03232b0c0c8 |
| Image Base | 0x00400000 |
| Entry Point | 0x00424530 |
| Compilation Time | 2023-02-20 14:50:28 |
| Checksum | 0x011de158 (Actual: 0x011de158) |
| OS Version | 5.0 |
| PEiD Signatures |
PE32 executable (GUI) Intel 80386, for MS Windows
|
| Digital Signature | OK |
| Imports |
6 libraries
kernel32, version, user32, oleaut32, netapi32, advapi32 |
| Exports | 2 functions |
| Resources | 22 Resources |
| Sections | 11 Sections |
Version Information
▼| Comments | Driver Updater |
| CompanyName | Outbyte |
| FileDescription | Outbyte Driver Updater Installation File |
| FileVersion | 2.2.3.15993 |
| LegalCopyright | Copyright © 2016-2023 Outbyte Computing Pty Ltd |
| OriginalFileName | Outbyte-driver-updater-setup.exe |
| ProductName | Driver Updater |
| ProductVersion | 2.x |
| Translation | 0x0000 0x04b0 |
PE Sections
▼| Name | Virtual Address | Virtual Size | Raw Size | Entropy | Characteristics | MD5 |
|---|---|---|---|---|---|---|
.text |
0x00001000 |
141,552 bytes | 141,824 bytes | 6.36 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
C4935C77B6DCCCDA129DACC031676833 |
.itext |
0x00024000 |
1,584 bytes | 2,048 bytes | 5.13 (Normal) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
EA0EF8DF4FB0583C656244E027E1DE80 |
.data |
0x00025000 |
6,064 bytes | 6,144 bytes | 3.63 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
82A719C709B9AE43588552CA35077EFA |
.bss |
0x00027000 |
23,844 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.idata |
0x0002d000 |
3,290 bytes | 3,584 bytes | 4.77 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
C7C00DD46505E21DD513C2AC9202B397 |
.didata |
0x0002e000 |
500 bytes | 512 bytes | 3.47 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
2BDA83A1C125A384429521517BD37097 |
.edata |
0x0002f000 |
116 bytes | 512 bytes | 1.35 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
1CA939239BA48E913FE26249E944A5D3 |
.tls |
0x00030000 |
20 bytes | 0 bytes | 0.00 (Normal) |
IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
D41D8CD98F00B204E9800998ECF8427E |
.rdata |
0x00031000 |
93 bytes | 512 bytes | 1.36 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
F6E17015BEC9014DE691418FB1506860 |
.reloc |
0x00032000 |
12,656 bytes | 12,800 bytes | 6.53 (Compressed) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
80B14D8A68DA7B649C2E18A2CAB8570E |
.rsrc |
0x00036000 |
306,116 bytes | 306,176 bytes | 2.71 (Normal) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
78685081739487440585373D6816075D |
Entropy Analysis Alert
1 section(s) with elevated entropy (≥6.5) - possible compression
Resource Analysis
▼| Resource Type | Count | Total Size | Percentage |
|---|---|---|---|
| RT_ICON | 8 | 297,352 bytes | |
| RT_STRING | 8 | 4,076 bytes | |
| RT_RCDATA | 3 | 629 bytes | |
| RT_GROUP_ICON | 1 | 118 bytes | |
| RT_VERSION | 1 | 852 bytes | |
| RT_MANIFEST | 1 | 1,792 bytes |
Certificate Chain Analysis
▼Certificate Information
| Product | Driver Updater |
| Description | Outbyte Driver Updater Installation File |
| File Version | 2.2.3.15993 |
| Original Name | Outbyte-driver-updater-setup.exe |
| Signing Date | 05:23 PM 02/23/2023 (1256 days ago) |
| Verification Status | Signed |
| Signers | Outbyte Computing Pty Ltd; DigiCert EV Code Signing CA (SHA2); DigiCert |
| Counter Signers | DigiCert Timestamp 2022 - 2; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert |
| Copyright | Copyright © 2016-2023 Outbyte Computing Pty Ltd |
Certificate Chain Summary
02 AC 5C 26 6A 0B 40 9B 8F 0B 79 F2 AE 46 25 770E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A0F 52 D7 29 DD F7 74 03 0A FE C8 D1 08 29 49 C507 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B03 F1 B4 E1 5F 3A 82 F1 14 96 78 B3 D7 D8 47 5C0C 4D 69 72 4B 94 FA 3C 2A 4A 3D 29 07 80 3D 5A✓ This file has been digitally signed and the certificate chain has been verified
- The signature ensures file integrity and authenticity from the publisher
- Timestamping proves when the signature was applied
Certificate Verification Status
OK
Remember: This is Result of Online Virus Scanner
Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:
Download Anti-Malware
Keep Your System Protected
This file appears clean, but regular security maintenance is important
-
1
Weekly Quick Scans: Set a reminder to run a scan every Sunday. Most infections are caught within the first week, so regular checks give you peace of mind.
-
2
Update Everything: Those annoying update popups exist for a reason — they patch security holes. Windows, browsers, Adobe, Java — keep them all current.
-
3
Download Smart: Stick to official websites and app stores. If a "free" version of paid software sounds too good to be true, it probably comes with unwanted extras.
-
4
Think Before You Click: Malware loves email attachments and "urgent" links. Even if an email looks like it's from your bank or a friend, verify suspicious requests through a different channel.
Leave a Comment
Gridinsoft Anti-Malware
Stay Malware-Free: Keep Your PC Protected with Gridinsoft Anti-Malware
Gridinsoft Anti-Malware offers just that—peace of mind with a robust, user-friendly solution that’s constantly updated to combat the latest threats. Designed by cybersecurity experts, it provides real-time protection and effortless malware removal. It’s not just about detecting threats; it's about enhancing your digital life with uninterrupted security. Give it a try and experience what it feels like to browse worry-free!