NRnR.exe

Norton Remove & Reinstall

Symantec Corporation

This is a setup and installation application. The file has been seen being downloaded from liveupdate.symantec.com and multiple other hosts.
Publisher:
Symantec Corporation  (signed and verified)

Product:
Norton Remove & Reinstall

Description:
Norton RnR

Version:
1.0.0.50

MD5:
a17af23858ff9e43f0d7cca5686b4934

SHA-1:
f888f49bd052e6fb2244aeabb7fc0cf57e76a229

SHA-256:
837386adc81477404ea6348fc714478ef26f1ad7845d41fce9b9dc66ff72e2d9

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
12/26/2024 12:45:21 AM UTC  (today)

File size:
5 MB (5,196,224 bytes)

Product version:
1.0

Copyright:
Copyright © 2011 Symantec Corporation. All rights reserved.

Original file name:
NRnR.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\downloads\nrnr.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
9/8/2010 2:00:00 AM

Valid to:
11/24/2013 12:59:59 AM

Subject:
CN=Symantec Corporation, OU=Symantec Research Labs, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Symantec Corporation, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2009-2 CA, OU=Terms of use at https://www.verisign.com/rpa (c)09, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
66660552D465B31F429F7527EA6A93BF

File PE Metadata
Compilation timestamp:
6/1/2011 3:10:47 PM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
9.0

CTPH (ssdeep):
98304:lsJ/kb1raXYtvSeqEHJYLeOpV7+phgIqvMWWU7w46jlM/Po9iY/g7bXELHEAprqy:GcRWYtvSeqEpYLeOpV7+pmIqvznT0+pW

Entry address:
0x2BB66B

Entry point:
E8, 21, 29, 01, 00, E9, 79, FE, FF, FF, 8B, FF, 55, 8B, EC, 83, EC, 10, 56, 8B, 75, 08, 57, 33, FF, 89, 7D, FC, 3B, F7, 75, 1E, E8, 74, 1D, 00, 00, 6A, 16, 5E, 57, 57, 57, 57, 57, 89, 30, E8, 32, A2, FF, FF, 83, C4, 14, 8B, C6, E9, 0B, 02, 00, 00, 6A, 24, 68, FF, 00, 00, 00, 56, E8, DA, 9C, FF, FF, 8B, 45, 0C, 83, C4, 0C, 3B, C7, 74, CB, 8B, 08, 8B, 40, 04, 83, F8, FF, 89, 4D, F0, 89, 45, F4, 7F, 16, 7C, 08, 81, F9, 40, 57, FF, FF, 73, 0C, E8, 25, 1D, 00, 00, 6A, 16, 5E, 89, 30, EB, BC, 83, F8, 07, 7C, 0A...
 
[+]

Code size:
3.2 MB (3,393,024 bytes)

The file NRnR.exe has been seen being distributed by the following 2 URLs.