NPE.exe

Norton Power Eraser

Symantec Corporation

This is a setup program which is used to install the application. This is installed with Norton PC Checkup. The file has been seen being downloaded from gsf-cf.softonic.com and multiple other hosts.
Publisher:
Symantec Corporation  (signed and verified)

Product:
Norton Power Eraser

Version:
2.0.0.52

MD5:
4e70653bd62d0174f761bd95895b09a2

SHA-1:
dfaefee870c212a5768d128c07bdd7c88dd29e14

SHA-256:
1fa3bf8120d6bf7430f2bf300861345bae19b058c96f164e21ea0df1fd365898

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/2/2024 3:38:25 PM UTC  (today)

File size:
2.4 MB (2,558,968 bytes)

Product version:
2.0

Copyright:
Copyright (c) 1997-2011 Symantec Corporation

Original file name:
NPE.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\npe.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/7/2010 5:00:00 PM

Valid to:
11/23/2013 3:59:59 PM

Subject:
CN=Symantec Corporation, OU=Symantec Research Labs, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Symantec Corporation, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
66660552D465B31F429F7527EA6A93BF

File PE Metadata
Compilation timestamp:
6/1/2011 2:30:43 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
49152:G0VDU6FAce+6zvPs7NkiE+EBhDi+2dnMfcjmx+KVa5aiXva:G0VDU6FAceN+0DivSUjmx+Kg5ai

Entry address:
0x1000

Entry point:
B8, 28, 6F, B6, 00, 50, 64, FF, 35, 00, 00, 00, 00, 64, 89, 25, 00, 00, 00, 00, 33, C0, 89, 08, 50, 45, 43, 6F, 6D, 70, 61, 63, 74, 32, 00, 45, 73, 94, 64, 9E, 2E, E4, 93, 93, 01, 60, BD, 4E, 70, 17, 05, 4A, 81, F1, B2, 2F, 8C, DE, 83, C2, E9, 9B, 07, FA, 75, EE, DD, B5, B2, 60, D0, 4A, 31, B7, B9, 85, 54, 31, EF, A9, 02, 00, CB, 24, 14, F5, 06, 1B, 8A, AD, 19, C3, BD, A2, 16, 5B, D1, 90, E4, CC, E5, 66, 92, 2F, E0, 35, 01, 52, 2E, CD, 2D, 7D, 1A, AE, A1, DF, 16, 0C, F5, 85, C0, 85, A8, C8, 55, FA, 25, FC...
 
[+]

Entropy:
7.9950

Packer / compiler:
PECompact v2

Code size:
4.8 MB (5,053,952 bytes)

The file NPE.exe has been discovered within the following program.

Norton PC Checkup  by Symantec Corporation
Norton PC Checkup is a program downloaded either separately or as a bundle with updates to Adobe Flash, provided to enable users to perform a system checkup of their Microsoft Windows based personal computers.
http:/www.norton.com/NortonLive
52% remove it
 
Powered by Should I Remove It?

The file NPE.exe has been seen being distributed by the following 10 URLs.

http://gsf-cf.softonic.com/dfa/efe/.../file?SD_used=0&channel=WEB&fdh=no&id_file=95651&instance=softonic_en&type=PROGRAM&Expires=1423550359&Key-Pair-Id=APKAJUA62FNWTI37JTGQ&Signature=Bu3-JF1h2fPsSXiv~JDWL1GKe9OgViSqQ6XK1sv-x-hAlNsxp2yniEfm2C9osGxL-ZaKs4m2wdGRMm0RyhJO8N~uOR0cbm2iFN31~o1xh9hyzDN2wExfbm5Wd1YSQj6uIs~1EgdYQ0jQQGoVN1baFkDR7KxqSjt5eApApdEAd-k_&filename=NPE.exe

http://global-shared-files-l3.softonic.com/dfa/efe/.../file?nvb=20140702054356&nva=20140702174456&token=0e4eab61fae7f75cd5f21&id_file=95651&channel=WEB&instance=softonic_en&type=PROGRAM&fdh=no&SD_used=0&filename=NPE.exe