evernote_4.5.10.7472.exe

Evernote

EVERNOTE CORPORATION

This is a setup and installation application. The file has been seen being downloaded from download1587.mediafire.com and multiple other hosts.
Publisher:
Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041  (signed by EVERNOTE CORPORATION)

Product:
Evernote

Description:
Evernote Installation Package

Version:
4,5,10,7472

MD5:
3f10d296781f9e36cea403dda4b11309

SHA-1:
2e5e2c8a7017b1ecdc9b70ce332a4c388c2cd59c

SHA-256:
124e425c05a9d735e62a299481f9367a2210006696bb34e2d844c284495b63f1

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/15/2024 5:59:41 AM UTC  (today)

File size:
50.7 MB (53,123,936 bytes)

Product version:
4,5,10,7472

Copyright:
Copyright 2012 Evernote Corporation. All rights reserved.

Original file name:
Setup.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\users\{user}\appdata\local\evernote\evernote\autoupdate\evernote_4.5.10.7472.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
9/19/2011 8:00:00 AM

Valid to:
11/8/2013 7:59:59 AM

Subject:
CN=EVERNOTE CORPORATION, O=EVERNOTE CORPORATION, L=Sunnyvale, S=California, C=US

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
358C15EEFDD33C61C0158BADEEAEC2D7

File PE Metadata
Compilation timestamp:
10/27/2012 6:41:33 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
786432:/QZv7c84UtvOzAVYkLtJxAhlulwCiEHizqZtqv/YoCaQk7EutOHYe6B1adTCWsD:/q7AoGzAVvzxATulwdwi8qYoC0CRImvA

Entry address:
0x17E8A

Entry point:
E8, 64, B7, 00, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 51, 53, 56, 8B, 75, 08, F6, 46, 0C, 40, 57, BB, B0, CC, 43, 00, 0F, 85, 72, 01, 00, 00, 56, E8, 1D, 7C, 00, 00, 59, 83, F8, FF, 74, 2E, 56, E8, 11, 7C, 00, 00, 59, 83, F8, FE, 74, 22, 56, E8, 05, 7C, 00, 00, C1, F8, 05, 56, 8D, 3C, 85, 60, EC, 43, 00, E8, F5, 7B, 00, 00, 83, E0, 1F, 59, C1, E0, 06, 03, 07, 59, EB, 02, 8B, C3, F6, 40, 24, 7F, 74, 4F, FF, 4E, 04, 78, 0A, 8B, 0E, 0F, B6, 01, 41, 89, 0E, EB, 07, 56, E8, 56, 84, 00, 00, 59, 83, F8, FF...
 
[+]

Entropy:
7.9699  (probably packed)

Code size:
191 KB (195,584 bytes)

The file evernote_4.5.10.7472.exe has been discovered within the following programs.

CCleaner  by Piriform
CCleaner developed by Piriform, is a utility program used to clean potentially unwanted files and invalid Windows Registry entries from a computer.
www.piriform.com/ccleaner
3% remove it
CMA Download Manager  by Classical Archives
classicalarchives.com/download-manager/index.html
About 17% of users remove it
Freeraser  by Codyssey.com
www.codyssey.com
About 6% of users remove it
Nexus Radio  by Talam Group, LLC
Some versions of Nexus Radio bundle a branded version of the Conduit Toolbar, which delivers search based advertising and results. During installation the user is presented with the option to install the toolbar. Once accepted, the packaged executable, ConduitInstaller.
www.nexusradio.com
About 11% of users remove it
Speccy  by Piriform
Speccy is a tool that allows the user to see information about hardware and software of the computer.
www.piriform.com/speccy
11% remove it
Vista Services Optimizer  by Smart PC Utilities
Publisher's description - “Vista Services Optimizer is an open source system tweaking software that enables you to optimize Windows services in an easy, automatic and safe way based on the way you use your computer.”
www.smartpcutilities.com/servicesoptimizer.html
73% remove it
 
Powered by Should I Remove It?

The file evernote_4.5.10.7472.exe has been seen being distributed by the following 5 URLs.

http://download1587.mediafire.com/02crq9k17syg/.../Evernote_4.5.10.7472.exe

Scan evernote_4.5.10.7472.exe - Powered by Reason Core Security