Gridinsoft Logo
File Icon

The Setup.exe (NoVirusThanks License Manager Service) File Analysis

Technical Analysis

File Name Setup.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.219.174
Database Version 2025-07-04 21:00:29 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
5,252,160
File Size (bytes)
2025-07-04
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
a6a3eb28af006be9d349760bce376184
SHA1
359c88593c67793e3447d71e0b2c710fb707f21a
SHA256
b2f713e1bba1fd2d520e5b41f7a9cdc974602117cc4405419576c833681fb844
SHA512
f65d13f5f341e2717e7d5baab5c1899fc3c235a593ac30503a515f7b0005893b4b1eef9a1706b8cee04976bcf1d4854167a1714c5eae4131f2c62794c25c3d28
ImpHash
38c12217c8213d41a3a956cb323b19d3

PE Analysis

Basic Information

Icon
Hash: 0074d2224ffff57f122adafa0488229a
Fuzzy: 6d6cf478a9a1f8b0e73cda662bf39eb6
dHash: 410e173333170c41
Image Base 0x00400000
Entry Point 0x00d99058
Compilation Time 2022-11-27 00:03:43
Checksum 0x0050d6a9 (Actual: 0x0050d6a9)
OS Version 5.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature OK
Imports 20 libraries
Exports 3 functions
Resources 9 Resources
Sections 18 Sections

Version Information

CompanyName NoVirusThanks Company Srl
FileDescription NoVirusThanks License Manager Service
FileVersion 1.0.0.0
LegalCopyright NoVirusThanks Company Srl
ProductName NoVirusThanks License Manager Service
ProductVersion 1.0.0.0
ProgramID com.embarcadero.MyServicePrj
Translation 0x0409 0x04e4

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
0x00001000 2,940,008 bytes 1,037,824 bytes 7.98 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ AC479E3FFD6B857E6A2ECF76E663995E
0x002cf000 8,972 bytes 5,120 bytes 7.83 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ D4DBB57F4D1C0E0613A4CC0B5122AB10
0x002d2000 133,144 bytes 34,304 bytes 7.92 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 6FADB15E79F760D4EF84B88AA490D5F0
.bss 0x002f3000 45,316 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
0x002ff000 16,342 bytes 1,536 bytes 7.31 (Compressed) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 24940A9058E793850E47FCEA460BC355
0x00303000 2,706 bytes 1,024 bytes 7.65 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 834A0C3908AD843F8EC85A93C7DFFD71
0x00304000 158 bytes 512 bytes 2.40 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 9223DB11C4FE4889E515777AC9F1A7BF
.tls 0x00305000 72 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
0x00306000 93 bytes 512 bytes 2.66 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 3C152134D14ED9E3AAABDA35BB24920B
0x00307000 258,588 bytes 144,896 bytes 7.98 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 6646EA6BC426A6ED2CC7040F9692D56A
0x00347000 157,696 bytes 19,968 bytes 7.97 (Packed/Encrypted) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 1BF7CBA0B6FB994AFBF605123F438052
.edata 0x0036e000 4,096 bytes 512 bytes 1.98 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 8DAC47FD3B1A181128A2DD9D16CBE2DF
.idata 0x0036f000 4,096 bytes 1,536 bytes 3.81 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE BCC9B20001E10D4474250E95B527DD7F
.tls 0x00370000 4,096 bytes 512 bytes 0.09 (Normal) IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 83AFB3ECC704D7CF1674652AF28E4E2A
.rsrc 0x00371000 103,424 bytes 103,424 bytes 2.36 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 8E3459835BBBF4F7124B8DACBB171300
.themida 0x0038b000 6,348,800 bytes 0 bytes 0.00 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE D41D8CD98F00B204E9800998ECF8427E
.boot 0x00999000 3,889,152 bytes 3,889,152 bytes 7.94 (Packed/Encrypted) IMAGE_SCN_CNT_CODE|IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 42E506D3E436DE0C5DDC4A98509FD1BE
.reloc 0x00d4f000 4,096 bytes 16 bytes 2.20 (Normal) IMAGE_SCN_MEM_READ B32F1F5830A90B607D41D6B310251DB2
Entropy Analysis Alert

7 section(s) with high entropy (≥7.5) detected - possible packing/encryption

1 section(s) with elevated entropy (≥6.5) - possible compression

Resource Analysis

Total Resources: 9 (102,373 bytes)
Resource Type Count Total Size Percentage
RT_ICON 5 99,592 bytes
97.3%
RT_STRING 1 404 bytes
0.4%
RT_GROUP_ICON 1 76 bytes
0.1%
RT_VERSION 1 804 bytes
0.8%
RT_MANIFEST 1 1,497 bytes
1.5%

Certificate Chain Analysis

Certificate Information
Product NoVirusThanks License Manager Service
Description NoVirusThanks License Manager Service
File Version 1.0.0.0
Signing Date 12:07 AM 11/27/2022 (950 days ago)
Verification Status Signed
Signers NoVirusThanks Company Srl; GlobalSign CodeSigning CA - SHA256 - G3; GlobalSign Root CA - R3
Counter Signers Globalsign TSA for Advanced - G4; GlobalSign Timestamping CA - SHA384 - G4; GlobalSign; GlobalSign Root CA - R3
Copyright NoVirusThanks Company Srl
Certificate Chain Summary
GlobalSign CodeSigning CA - SHA256 - G3 #1 Primary
Validity Period: 2016-06-15 00:00:00 → 2024-06-15 00:00:00
Signature Algorithm: sha256RSA
Serial Number: 48 1B 6A 07 26 D2 E8 3F 26 02 D4 82 5A CD
NoVirusThanks Company Srl #2 Chain
Validity Period: 2020-11-23 10:31:32 → 2024-02-23 10:31:32
Signature Algorithm: sha256RSA
Serial Number: 0E FF 23 6F AC 7D EA 42 9E 95 F5 9E
Globalsign TSA for Advanced - G4 #3 Chain
Validity Period: 2022-04-06 07:44:12 → 2033-05-08 07:44:12
Signature Algorithm: sha256RSA
Serial Number: 01 C2 9C 7A F4 7A A6 02 58 0E AF 32 B1 23 B1 1D
GlobalSign Timestamping CA - SHA384 - G4 #4 Chain
Validity Period: 2018-06-20 00:00:00 → 2034-12-10 00:00:00
Signature Algorithm: sha384RSA
Serial Number: 01 EC 1C 92 40 DE FD 2E 40 5D 7C 47 74
GlobalSign #5 Chain
Validity Period: 2019-02-20 00:00:00 → 2029-03-18 10:00:00
Signature Algorithm: sha384RSA
Serial Number: 01 F2 40 42 40 CE FD 22 DB E9 6C 71 FC
GlobalSign #6 Chain
Validity Period: 2009-03-18 10:00:00 → 2029-03-18 10:00:00
Signature Algorithm: sha256RSA
Serial Number: 04 00 00 00 00 01 21 58 53 08 A2

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware