Gridinsoft Logo

The InfoForSetup.exe File Analysis

Technical Analysis

File Name InfoForSetup.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.212.174
Database Version 2025-04-07 10:01:00 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
99,264
File Size (bytes)
2025-04-07
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
c4f9e1fe829df9392f4ac1585675e1f4
SHA1
46ad374321f55013d39cab5a707f4b814268f964
SHA256
8c1e85d80e3c0dbf5790d15730dd2ea940743305e34db429e866df3904018bc6
SHA512
ac9dfb6fd277b8ce1573b663f89e5e6b6892f419a3d2897c2a44764f801a325289edfec2b763efb4fa13b1019a864c284fef39260c9fb0dc7e9455c1ffe961c1
ImpHash
9efee973798dd4873bbf503f5c806ab9

PE Analysis

Basic Information

Image Base 0x00400000
Entry Point 0x00402db2
Compilation Time 2024-07-11 08:21:15
Checksum 0x00024158 (Actual: 0x00024158)
OS Version 6.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
PDB Path J:\svn\epm\ShareLib\aliyunlog\Release\InfoForSetup.pdb
Digital Signature OK
Imports 2 libraries
KERNEL32, SHELL32
Exports 0 functions
Resources 1 Resources
Sections 5 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 55,791 bytes 55,808 bytes 6.61 (Compressed) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 7D9669B72F8A896A5959EB6A47179B60
.rdata 0x0000f000 25,000 bytes 25,088 bytes 4.85 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ CACD5E099B3C91831288C582F6D9AA27
.data 0x00016000 4,944 bytes 2,048 bytes 2.27 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BE69E264EC91852BBE34EFF9D07D60AE
.rsrc 0x00018000 480 bytes 512 bytes 4.70 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9124B0CEC9B7677B6C6AFA99416F02A3
.reloc 0x00019000 3,972 bytes 4,096 bytes 6.48 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ F73FDEFC4A26E53813BA13AACE386525
Entropy Analysis Alert

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 1 (381 bytes)
Resource Type Count Total Size Percentage
RT_MANIFEST 1 381 bytes
100%

Certificate Chain Analysis

Certificate Information
Signing Date 07:44 AM 11/18/2024 (199 days ago)
Verification Status Signed
Signers CHENGDU YIWO Tech Development Co., Ltd.; DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1; DigiCert Trusted Root G4; DigiCert
Counter Signers DigiCert Timestamp 2024; DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA; DigiCert Trusted Root G4; DigiCert
Certificate Chain Summary
DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1 #1 Primary
Validity Period: 2021-04-29 00:00:00 → 2036-04-28 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 08 AD 40 B2 60 D2 9C 4C 9F 5E CD A9 BD 93 AE D9
CHENGDU YIWO Tech Development Co., Ltd. #2 Chain
Validity Period: 2024-07-09 00:00:00 → 2027-07-09 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 04 44 A4 D0 F5 97 15 99 6A BF 0C 2B 81 F2 C8 DD
DigiCert Timestamp 2024 #3 Chain
Validity Period: 2024-09-26 00:00:00 → 2035-11-25 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 0B AE 66 BC 5A BA 7F 95 87 C6 F9 E9 04 E3 33 04
DigiCert Trusted G4 RSA4096 SHA256 TimeStamping CA #4 Chain
Validity Period: 2022-03-23 00:00:00 → 2037-03-22 23:59:59
Signature Algorithm: sha256RSA
Serial Number: 07 36 37 B7 24 54 7C D8 47 AC FD 28 66 2A 5E 5B
DigiCert Trusted Root G4 #5 Chain
Validity Period: 2022-08-01 00:00:00 → 2031-11-09 23:59:59
Signature Algorithm: sha384RSA
Serial Number: 0E 9B 18 8E F9 D0 2D E7 EF DB 50 E2 08 40 18 5A

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware