mbam-msp.exe

Malwarebytes Anti-Malware

Malwarebytes Corporation

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Malwarebytes Anti-Malware (reboot)’.
Publisher:
Malwarebytes Corporation  (signed and verified)

Product:
Malwarebytes Anti-Malware

Description:
Malwarebytes Anti-Malware (MSP)

Version:
1.62.0087

MD5:
78041a8ec1785f3b65ac6918588fc707

SHA-1:
24dafae094718cf6ecac673d09462480af57bd05

SHA-256:
aa1cb744715bf44893ccdfb14a8495805ad5d95a86263af54b94d45a911f2376

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 12:13:12 AM UTC  (today)

File size:
946.7 KB (969,392 bytes)

Product version:
1.62.0087

Copyright:
© Malwarebytes Corporation. All rights reserved.

Original file name:
mbam-msp.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/23/2011 8:00:00 PM

Valid to:
6/4/2013 7:59:59 PM

Subject:
CN=Malwarebytes Corporation, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Malwarebytes Corporation, L=San Jose, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
635725F2493191F6F4F686234034FE80

File PE Metadata
Compilation timestamp:
5/30/2012 10:22:09 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

Entry address:
0x2A58

Entry point:
68, 28, 33, 40, 00, E8, F0, FF, FF, FF, 00, 00, 60, 00, 00, 00, 30, 00, 00, 00, 58, 00, 00, 00, 38, 00, 00, 00, 91, 77, B5, D3, C6, 4C, 8C, 49, BE, A7, 0C, C0, AC, B7, BA, 3C, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 00, 00, 00, 00, 6D, 62, 61, 6D, 00, 00, 00, 00, 4D, 61, 6C, 77, 61, 72, 65, 62, 79, 74, 65, 73, 27, 20, 41, 6E, 74, 69, 2D, 4D, 61, 6C, 77, 61, 72, 65, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, 00, D8, 00, 00, 00, A8, 00, 00, 00, 00, 00, 00, 00, 02, 00, 00, 00, 08, 00, 00, 00...
 
[+]

Entropy:
6.3584

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
404 KB (413,696 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Malwarebytes Anti-Malware (reboot)

Command:
"C:\sinu\malwarebytes\mbam-msp.exe" \runcleanupscript