× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: d17e070188c2373ce7b6e2fdba3b87810651b374d6130db75acf80dd17f28a98
File name: NoNotifyAvira-v4.0.1.exe
Detection ratio: 4 / 43
Analysis date: 2011-05-24 16:39:58 UTC ( 6 years, 6 months ago ) View latest
Antivirus Result Update
AntiVir TR/ATRAPS.Gen 20110524
Jiangmin TrojanDownloader.Generic.cuk 20110524
McAfee-GW-Edition Heuristic.BehavesLike.Win32.ModifiedUPX.F!84 20110524
Panda Suspicious file 20110524
AhnLab-V3 20110524
Antiy-AVL 20110524
Avast 20110524
Avast5 20110524
AVG 20110524
BitDefender 20110524
CAT-QuickHeal 20110524
ClamAV 20110524
Commtouch 20110524
Comodo 20110524
DrWeb 20110524
Emsisoft 20110524
eSafe 20110522
eTrust-Vet 20110524
F-Prot 20110524
F-Secure 20110524
Fortinet 20110522
GData 20110524
Ikarus 20110524
K7AntiVirus 20110524
Kaspersky 20110524
McAfee 20110524
Microsoft 20110524
NOD32 20110524
Norman 20110524
nProtect 20110524
PCTools 20110519
Prevx 20110524
Rising 20110524
Sophos AV 20110524
SUPERAntiSpyware 20110524
Symantec 20110524
TheHacker 20110523
TrendMicro 20110524
TrendMicro-HouseCall 20110524
VBA32 20110524
VIPRE 20110524
ViRobot 20110524
VirusBuster 20110523
The file being studied is a Portable Executable file! More specifically, it is a Win32 EXE file for the Windows command line subsystem.
FileVersionInfo properties
Copyright
fred_151 -- fred151.altervista.org

Product No Notify Avira
Internal name No Notify Avira
File version 4,0,0,1
Description This program removes the advertisement of updating and startup splash screen of Avira Antivir
Packers identified
F-PROT UPX_LZMA
PEiD UPX 2.93 [LZMA] -> Markus Oberhumer, Laszlo Molnar & John Reiser
PE header basic information
Target machine Intel 386 or later processors and compatible processors
Compilation timestamp 2010-11-08 13:12:00
Entry Point 0x00010770
Number of sections 3
PE sections
PE imports
InitCommonControls
SetBkColor
VirtualFree
ExitProcess
VirtualProtect
LoadLibraryA
VirtualAlloc
GetProcAddress
CoInitialize
ShellExecuteExA
PathQuoteSpacesA
IsChild
Number of PE resources by type
RT_RCDATA 3
RT_ICON 1
RT_MANIFEST 1
RT_VERSION 1
RT_GROUP_ICON 1
Number of PE resources by language
NEUTRAL 7
PE resources
ExifTool file metadata
SubsystemVersion
4.0

LinkerVersion
2.5

ImageVersion
0.0

FileSubtype
0

FileVersionNumber
4.0.0.1

UninitializedDataSize
45056

LanguageCode
English (U.S.)

FileFlagsMask
0x003f

CharacterSet
Windows, Latin1

InitializedDataSize
8192

EntryPoint
0x10770

MIMEType
application/octet-stream

LegalCopyright
fred_151 -- fred151.altervista.org

FileVersion
4,0,0,1

TimeStamp
2010:11:08 14:12:00+01:00

FileType
Win32 EXE

PEType
PE32

InternalName
No Notify Avira

ProductVersion
4,0,0,1

FileDescription
This program removes the advertisement of updating and startup splash screen of Avira Antivir

OSVersion
4.0

FileOS
Windows 16-bit

Subsystem
Windows command line

MachineType
Intel 386 or later, and compatibles

CompanyName
Fred_151

CodeSize
24576

ProductName
No Notify Avira

ProductVersionNumber
4.0.0.1

FileTypeExtension
exe

ObjectFileType
Executable application

Compressed bundles
File identification
MD5 c090df6c6d7970d6ef3d3a4c58f91ebd
SHA1 047e831c90f00f047d777cde303aec2019bc43b8
SHA256 d17e070188c2373ce7b6e2fdba3b87810651b374d6130db75acf80dd17f28a98
ssdeep
768:GGcAPQIpz0Mb18Kdt14yvLhlkeIrnbcuyD7UJQX:+3TMb1FpPt/Irnouy8JQ

authentihash 90cd75256b60a3efabdc86bdbc15c1cb67df9da15bfb5d2286e7cda25e3a92ea
imphash 1d88d597200c0081784c27940d743ec5
File size 27.5 KB ( 28160 bytes )
File type Win32 EXE
Magic literal
PE32 executable for MS Windows (console) Intel 80386 32-bit

TrID UPX compressed Win32 Executable (39.3%)
Win32 EXE Yoda's Crypter (38.6%)
Win32 Dynamic Link Library (generic) (9.5%)
Win32 Executable (generic) (6.5%)
Generic Win/DOS Executable (2.9%)
Tags
peexe upx

VirusTotal metadata
First submission 2011-05-24 16:39:58 UTC ( 6 years, 6 months ago )
Last submission 2017-04-16 19:09:40 UTC ( 7 months, 1 week ago )
File names file-2440582_exe
smona131739414339272528155
smona132769658256913248504
NoNotifyAvira-v4.0.1.exe
smona132410309474966675502
smona_d17e070188c2373ce7b6e2fdba3b87810651b374d6130db75acf80dd17f28a98.bin
No Notify Avira
NoNotifyAvira-v4.0.1.exe
NoNotifyAvira_4.0.1.exe
smona131959863900943957048
file-3006964_exe
c090df6c6d7970d6ef3d3a4c58f91ebd.exe
NoNotifyAvira-v4.0.1.exe
c090df6c6d7970d6ef3d3a4c58f91ebd
smona132573433203828688106
smona131060412627164916718
smona131907540706860676834
smona132252539396773808619
NoNotifyAvira 4.0.1.exe
No Notify Avira v4.0.1.exe
smona130633260051510468153
Advanced heuristic and reputation engines
ClamAV
Possibly Unwanted Application. While not necessarily malicious, the scanned file presents certain characteristics which depending on the user policies and environment may or may not represent a threat. For full details see: https://www.clamav.net/documents/potentially-unwanted-applications-pua .

Symantec reputation Suspicious.Insight
No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!