Au_.exe

Viber

Viber Media Inc.

(Note, the name of the file is not always 'AU_.exe'; the NullSoft NSIS uninstaller changes the original name while copying it to the temporary directory.) The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. This is installed with Viber.
Publisher:
Viber Media Inc  (signed by Viber Media Inc.)

Product:
Viber

Description:
Viber Uninstall

Version:
3.0.0.134152

MD5:
f23a49f9b7bd70f4588eb396aadcbf0f

SHA-1:
0624a7fa5bbc590478944259d66b848022ea4ee1

SHA-256:
27184b8d6d3abb29c9129d0a5784b97f2e7e0f37f2a89245d7df5f678ffa002c

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/27/2024 1:42:40 AM UTC  (today)

File size:
282.3 KB (289,104 bytes)

Product version:
3.0.0.134152

Copyright:
Copyright (c) 2012

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
Language Neutral

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\au_.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
3/28/2012 2:00:00 AM

Valid to:
3/29/2014 1:59:59 AM

Subject:
CN=Viber Media Inc., OU=DEV, O=Viber Media Inc., L=Panama, S=Panama, C=PA

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
73C6D14119B06C7562CA81A8BEFDCED1

File PE Metadata
Compilation timestamp:
5/30/2013 10:09:15 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:0X47Xe9YDU8A3TgKN0WITtH8qIsojZZyzsVQRcBlOCkqOoHKit:0XRY6g401ZHnCZZLVQRcBlO8/H

Entry address:
0x38AF

Entry point:
81, EC, D4, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 68, A2, 40, 00, 89, 6C, 24, 14, FF, 15, 30, 90, 40, 00, 68, 01, 80, 00, 00, FF, 15, B4, 90, 40, 00, 55, FF, 15, BC, 92, 40, 00, 6A, 08, A3, 98, EB, 47, 00, E8, 25, 2A, 00, 00, 55, 68, B4, 02, 00, 00, A3, B0, EA, 47, 00, 8D, 44, 24, 38, 50, 55, 68, 64, A2, 40, 00, FF, 15, 80, 91, 40, 00, 68, 4C, A2, 40, 00, 68, A0, 6A, 47, 00, E8, 8F, 27, 00, 00, FF, 15, B0, 90, 40, 00, 50, BF, A0, F0, 4C, 00, 57, E8, 7D, 27, 00, 00...
 
[+]

Entropy:
6.8657

Packer / compiler:
Nullsoft install system v2.x

Code size:
29.5 KB (30,208 bytes)

The file Au_.exe has been discovered within the following programs.

Viber  by Viber Media Inc
Publisher's description - “Viber for Windows lets you send free messages and make free calls to other Viber users, on any device and network, in any country! Viber syncs your contacts, messages and call history with your mobile device. All the stickers from your mobile phone, now on your desktop.”
www.viber.com/products/windows
About 3% of users remove it
 
Powered by Should I Remove It?

Scan Au_.exe - Powered by Reason Core Security