文件名 | MBSetup.exe |
文件类型 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
扫描器版本 | 1.0.227.174 |
数据库版本 | 2025-10-10 13:00:15 UTC |
我们的扫描器未检测到威胁
哈希类型 | 值 | 操作 |
---|---|---|
MD5 |
edcbb964b10523dea5c6a9616f17cd5b
|
|
SHA1 |
7752c05c20ef8bb8f9f522fae17bfab57c82bae3
|
|
SHA256 |
2913073395c78cbc67d2c6c8c191c71a7ada50aabf12e8315d6126d8fa9538d2
|
|
SHA512 |
5024aa53068763416b240e75d0dc0f50ade67fe9de8dd535e73506655e73a8432ec8842664d3ba45b92422eb9f144ce4a3faf95e4e92b7509bae3a5fee7f48c5
|
|
ImpHash |
d3c026afe97504ed51e97e42c40d0c29
|
图标 |
哈希: c811b162b64291b6dca0621d5667fec6
模糊: 7a3f04e0588d6a4d10b233fb88a3e1b1 dHash: 68aab2aaccccf030 |
映像基址 | 0x00400000 |
入口点 | 0x0045c11b |
编译时间 | 2022-12-06 00:23:21 |
校验和 | 0x0027287a (实际: 0x0027287a) |
操作系统版本 | 6.0 |
PEiD 签名 |
PE32 executable (GUI) Intel 80386, for MS Windows
|
PDB 路径 | d:\jenkins\workspace\A_MB4_MBSetup\bin\Win32\Release\MBSetup.pdb |
数字签名 | OK |
导入 |
3 库
KERNEL32, CRYPT32, RPCRT4 |
导出 | 0 函数 |
资源 | 315 资源 |
节 | 5 节 |
CompanyName | Malwarebytes |
FileDescription | Malwarebytes Setup |
FileVersion | 4.5.19.299 |
LegalCopyright | Copyright (C) 2017 - 2021 Malwarebytes, Inc. All rights reserved. |
InternalName | MBSetup.exe |
OriginalFilename | MBSetup.exe |
ProductName | Malwarebytes |
Translation | 0x0409 0x04b0 |
名称 | 虚拟地址 | 虚拟大小 | 原始大小 | 熵 | 特征 | MD5 |
---|---|---|---|---|---|---|
.text |
0x00001000 |
650,104 bytes | 650,240 bytes | 6.58 (压缩) |
IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ
|
8D7164913ED2F5A9E26ECECBBDF755B7 |
.rdata |
0x000a0000 |
164,088 bytes | 164,352 bytes | 5.06 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
027546A8B11581DD084E5C3DD66D2953 |
.data |
0x000c9000 |
22,492 bytes | 16,896 bytes | 4.64 (正常) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE
|
04860BE299E3D2A2D001003354A8AFD6 |
.rsrc |
0x000cf000 |
1,599,656 bytes | 1,600,000 bytes | 6.90 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ
|
7DB61FDF1B3FD11CB7B1C406CD21D0B4 |
.reloc |
0x00256000 |
38,580 bytes | 38,912 bytes | 6.67 (压缩) |
IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ
|
591ED7438C875C9DF862FD61FEC8AFE3 |
3 检测到较高熵(≥6.5)的节 - 可能存在压缩
资源类型 | 数量 | 总大小 | 百分比 |
---|---|---|---|
BINARY | 2 | 335,596 字节 | |
PNG | 64 | 574,082 字节 | |
RESOURCEFILE | 2 | 123,218 字节 | |
RT_BITMAP | 4 | 97,876 字节 | |
RT_ICON | 6 | 116,841 字节 | |
RT_DIALOG | 9 | 5,210 字节 | |
RT_STRING | 225 | 332,754 字节 | |
RT_GROUP_ICON | 1 | 90 字节 | |
RT_VERSION | 1 | 764 字节 | |
RT_MANIFEST | 1 | 2,082 字节 |
产品 | Malwarebytes |
描述 | Malwarebytes Setup |
文件版本 | 4.5.19.299 |
原始名称 | MBSetup.exe |
签名日期 | 12:27 AM 12/06/2022 (1039 天前) |
验证状态 | Signed |
签名者 | Malwarebytes Inc.; Sectigo RSA Code Signing CA 2; USERTrust RSA Certification Authority; Sectigo (AAA) |
副签名者 | Microsoft Public RSA Time Stamping Authority; Microsoft Public RSA Timestamping CA 2020; Microsoft Identity Verification Root Certificate Authority 2020 |
内部名称 | MBSetup.exe |
版权 | Copyright (C) 2017 - 2021 Malwarebytes, Inc. All rights reserved. |
39 72 44 3A F9 22 B7 51 D7 D3 6C 10 DD 31 35 95
A6 57 F7 78 B3 1A E5 23 D6 67 13 17 18 D1 6E B2
9E 02 B0 E9 4A CE B2 10 9C A1 E9 83 6B E0 C2 DB
33 00 00 00 05 E5 CF 0F FF 66 2E C9 87 00 00 00 00 00 05
33 00 00 00 1D AE C9 44 A1 CE 22 00 AB 00 00 00 00 00 1D
54 98 D2 D1 D4 5B 19 95 48 13 79 C8 11 C0 87 99
33 00 00 4C 88 DF 71 3F D6 E8 75 41 A3 00 00 00 00 4C 88
33 00 00 00 07 37 8C 5B A1 D9 5B 8C D4 00 00 00 00 00 07
33 00 00 00 07 87 A3 34 A3 7B A5 8E 1C 00 00 00 00 00 07
33 00 00 00 1E 13 57 DA 40 37 CD FC 82 00 00 00 00 00 1E
✓ 此文件已进行数字签名,证书链已验证。
OK
Gridinsoft Anti-Malware 拥有更强大的病毒扫描引擎。我们建议使用它来更准确地诊断受感染的系统。这个简短的指南将帮助您安装我们的旗舰产品以进行更准确的诊断:
下载反恶意软件此文件看起来是干净的,但定期的安全维护很重要