nocr.exe

OverZone Software

Publisher:
OverZone Software  (signed and verified)

MD5:
4e403db968b27319b64b8d1f3567f09c

SHA-1:
1fdc07ffc578d2885da08d9f11e42b22aaedc8dd

SHA-256:
d70c879e9fe09b393b236e63a144f3713d8e35f4ad96921fc4a18837c8e350ac

Scanner detections:
2 / 68

Status:
Clean  (2 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/24/2024 4:31:28 PM UTC  (today)

Scan engine
Detection
Engine version

McAfee
Artemis!4E403DB968B2
5600.7240

nProtect
Trojan/W32.Agent.33600.B
10.07.12.01

File size:
32.8 KB (33,600 bytes)

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\source code library\data\nocr.exe

Digital Signature
Authority:
GeoTrust Inc.

Valid from:
12/12/2007 11:33:04 AM

Valid to:
12/25/2008 11:33:04 AM

Subject:
E=software-contact@highdots.com, CN=OverZone Software, OU=Email and phone validated only., OU=Phone Validation - 216 71334667, OU=See Public S/MIME CPS www.geotrust.com/resources/CPS., OU=CPS terms incorporated by reference liability limited.

Issuer:
CN=GeoTrust True Credentials CA 2, O=GeoTrust Inc., C=US

Serial number:
1081B9

File PE Metadata
Compilation timestamp:
6/20/1992 1:22:17 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
768:fiwxqsQOuLy9BNnwWtWgvL/7wPumOr850P4V:awxqsQ+nwsLvL/8GEj

Entry address:
0x345C

Entry point:
55, 8B, EC, 83, C4, F0, B8, 24, 34, 40, 00, E8, 5C, FE, FF, FF, 68, 20, 10, 01, 00, 68, A0, 34, 40, 00, 68, CC, 34, 40, 00, 6A, 00, E8, FA, FE, FF, FF, 6A, 01, 6A, 00, 6A, 00, 68, A0, 37, 40, 00, 68, 54, 38, 40, 00, 6A, 00, E8, 23, FF, FF, FF, E8, 5E, F9, FF, FF, 00, 00, 53, 6F, 75, 72, 63, 65, 20, 43, 6F, 64, 65, 20, 4C, 69, 62, 72, 61, 72, 79, 20, 2D, 20, 53, 65, 63, 75, 72, 69, 74, 79, 20, 43, 68, 65, 63, 6B, 20, 45, 72, 72, 6F, 72, 00, 00, 2A, 2A, 2A, 20, 53, 65, 63, 75, 72, 69, 74, 79, 20, 43, 68, 65...
 
[+]

Entropy:
6.1330

Developed / compiled with:
Microsoft Visual C++

Code size:
10.5 KB (10,752 bytes)

Scan nocr.exe - Powered by Reason Core Security