Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5,4,1,3962 2.08%
5,4,0,3698 2.08%
5,1,2,2387 2.08%
5,0,3,1614 12.50%
5,0,2,1392 4.17%
4,6,6,8360 25.00%
4,6,5,8345 2.08%
4,6,4,8136 20.83%
4,6,3,8096 16.67%
4,6,2,7927 10.42%
4,6,1,7860 2.08%

Relationships

Parent processes
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExW, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegEnumKeyExW, RegSetValueExW, RegQueryInfoKeyW, RegDeleteKeyW, ConvertStringSecurityDescriptorToSecurityDescriptorW
comctl32.dll
_TrackMouseEvent, ImageList_LoadImageW, ImageList_GetIconSize, ImageList_Draw, InitCommonControlsEx
encrashrep.dll
EnCrashRepExceptionFilter
gdi32.dll
GetDeviceCaps, GetClipBox, SetWindowOrgEx, LPtoDP, DPtoLP, Rectangle, GetPixel, SetDIBColorTable, GetDIBColorTable, StretchBlt, CreatePen, Polygon, LineTo, MoveToEx, CreateCompatibleBitmap, SetBkMode, CreateFontIndirectW, CreateCompatibleDC, CreateDIBSection, BitBlt, ExtCreateRegion, CombineRgn, CreateDIBitmap, GetObjectW, GetDIBits, CreateSolidBrush, SetTextColor, SelectObject, DeleteDC, DeleteObject, SetBkColor, ExtTextOutW, CreateFontW, GetTextMetricsW, RestoreDC, SaveDC, GetBkColor
gdiplus.dll
GdipBitmapUnlockBits, GdipGetImagePalette, GdipCreateBitmapFromScan0, GdipBitmapLockBits, GdiplusStartup, GdipGetImagePixelFormat, GdipGetImageHeight, GdipGetImageWidth, GdipDrawImageI, GdipDeleteGraphics, GdiplusShutdown, GdipAlloc, GdipCreateBitmapFromStream, GdipCreateBitmapFromStreamICM, GdipFree, GdipDisposeImage, GdipCloneImage, GdipGetImageGraphicsContext, GdipGetImagePaletteSize
kernel32.dll
FlushFileBuffers, ReadFile, CreateNamedPipeW, ConnectNamedPipe, PeekNamedPipe, WriteFile, TerminateProcess, QueryPerformanceCounter, QueryPerformanceFrequency, GlobalFree, GlobalReAlloc, GlobalUnlock, GlobalLock, GlobalAlloc, SetThreadPriority, GetProcessId, lstrcpynW, GetModuleHandleExW, MulDiv, GetTickCount, ResetEvent, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, InitializeCriticalSectionAndSpinCount, GetStringTypeW, GetStringTypeA, LCMapStringA, GetLocaleInfoA, CreateFileA, SetStdHandle, GetConsoleMode, GetConsoleCP, GetSystemTimeAsFileTime, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, LCMapStringW, GetStartupInfoA, GetFileType, SetHandleCount, GetModuleHandleA, HeapCreate, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, GetStdHandle, GetStartupInfoW, VirtualQuery, VirtualProtect, CreateThread, ExitThread, RtlUnwind, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, HeapSize, HeapReAlloc, HeapDestroy, VirtualAlloc, VirtualFree, IsProcessorFeaturePresent, LoadLibraryA, HeapAlloc, GetProcessHeap, HeapFree, InterlockedCompareExchange, ExitProcess, OutputDebugStringW, GetLocaleInfoW, FileTimeToSystemTime, CreateDirectoryW, SetEndOfFile, SetFilePointerEx, GetFileSizeEx, SetFilePointer, GetFileSize, CreateFileW, FindFirstFileW, MapViewOfFile, CreateFileMappingW, FindClose, FindNextFileW, UnmapViewOfFile, GetSystemInfo, GetFullPathNameW, DeleteFileW, GetFileAttributesExW, GetCurrentThreadId, SetLastError, LocalFree, FormatMessageW, DisconnectNamedPipe, TerminateThread, Sleep, GetVersionExW, LoadLibraryW, GetProcAddress, lstrcmpiW, MultiByteToWideChar, FreeLibrary, LoadLibraryExW, CreateMutexW, InterlockedExchange, SetErrorMode, GetLastError, GetModuleFileNameA, InterlockedDecrement, InterlockedIncrement, WideCharToMultiByte, GetExitCodeThread, ResumeThread, WaitForSingleObject, SetEvent, CloseHandle, CreateEventW, GetCurrentProcessId, GetSystemTime, GetLocalTime, LocalAlloc, GetModuleHandleW, GetModuleFileNameW, lstrlenW, FindResourceExW, LoadResource, LockResource, SizeofResource, FindResourceW, DeleteCriticalSection, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetCurrentProcess, FlushInstructionCache, RaiseException, SetEnvironmentVariableW, SetEnvironmentVariableA, CompareStringW, GetTempPathW, GetDriveTypeW
libpcre.dll
regfree, regexec, regcomp
libxml2.dll
xmlTextReaderIsValid, xmlTextReaderRead, xmlSetExternalEntityLoader, xmlTextReaderSetErrorHandler, xmlReaderForMemory, xmlTextReaderLocatorLineNumber, xmlTextReaderLocatorBaseURI, xmlFree, xmlNewInputFromFile, xmlNewStringInputStream, xmlNoNetExternalEntityLoader, xmlFreeTextReader
msimg32.dll
AlphaBlend, GradientFill, TransparentBlt
ole32.dll
CoInitializeEx, CoUninitialize, CoTaskMemFree, CoTaskMemAlloc, CoTaskMemRealloc, IIDFromString, CoCreateInstance
shell32.dll
ShellExecuteW, ShellExecuteExW, SHGetSpecialFolderPathW
shlwapi.dll
UrlCanonicalizeW, PathStripToRootW, PathFindFileNameW, UrlCombineW, PathBuildRootW, PathIsNetworkPathW, PathGetDriveNumberW
user32.dll
SendMessageW, ShowWindow, LoadImageW, GetMessageW, PeekMessageW, CharNextW, EndDialog, UnregisterClassA, TranslateMessage, InflateRect, GetSystemMetrics, SystemParametersInfoW, SetWindowTextW, EnableWindow, MessageBeep, PostQuitMessage, GetSysColor, GetWindowLongW, DrawTextW, DefWindowProcW, DestroyWindow, MapWindowPoints, GetSysColorBrush, CreateWindowExW, CallWindowProcW, SetWindowLongW, PostMessageW, GetWindowTextW, GetWindowTextLengthW, MoveWindow, SendMessageTimeoutW, AllowSetForegroundWindow, SetWindowPos, GetWindowRect, GetClientRect, ScreenToClient, InvalidateRect, SetFocus, GetParent, GetDlgItem, IsDialogMessageW, GetMonitorInfoW, MonitorFromWindow, GetWindow, GetWindowDC, UnionRect, DrawEdge, TrackMouseEvent, ReleaseDC, OffsetRect, GetClassInfoExW, LoadCursorW, RegisterClassExW, MessageBoxIndirectW, SetForegroundWindow, IsWindow, GetDesktopWindow, RegisterWindowMessageW, CreateDialogParamW, IsWindowEnabled, GetFocus, GetKeyState, EqualRect, IntersectRect, UpdateWindow, MonitorFromPoint, MonitorFromRect, SetCursor, CharLowerW, LoadBitmapW, CopyRect, GetWindowThreadProcessId, SetRectEmpty, PtInRect, IsRectEmpty, GetDC, EndPaint, BeginPaint, SetWindowRgn, SetCapture, KillTimer, SetTimer, IsWindowVisible, GetMessagePos, GetCapture, SetRect, SetLayeredWindowAttributes, ReleaseCapture, PostThreadMessageW, RegisterClipboardFormatW, DialogBoxParamW, EnumThreadWindows, FindWindowW, DispatchMessageW, DrawFocusRect
uxtheme.dll
OpenThemeData, CloseThemeData, DrawThemeBackground
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
wininet.dll
InternetCrackUrlW

evernoteclipper.exe

Evernote by EVERNOTE CORPORATION (Signed)

Remove evernoteclipper.exe
Version:   4,6,3,8096
MD5:   f51fc0a488290b55f7398ab3634a90bc
SHA1:   70e6b839ad1ff799dd64c4e5fc7caa7f3787c4f7
SHA256:   4a8b3f7e0349a93577eddc25c28c62ae7b234a8f17e941d8966707e9a9a84993

Overview

evernoteclipper.exe executes as a process with the local user's privileges usually within the context of Windows Explorer. During installation, it (or a shortcut) is added to the user's startup folder which is designed to automatically launch when the user logs into Windows. It is installed with a couple of know programs including Evernote v. 4.6.3 published by Evernote Corp., Evernote v. 4.6.3 from Evernote Corp. and Evernote v. 4.6.3 by Evernote Corp.. The file is digitally signed by EVERNOTE CORPORATION which was issued by the Thawte certificate authority (CA).

DetailsDetails

File name:evernoteclipper.exe
Publisher:Evernote Corp., 305 Walnut Street, Redwood City, CA 94063
Product name:Evernote®
Description:Evernote Clipper
Typical file path:C:\Program Files\evernote\evernote\evernoteclipper.exe
Original name:enclipper.exe
File version:4,6,3,8096
Size:1.04 MB (1,086,816 bytes)
Certificate
Issued to:EVERNOTE CORPORATION
Authority (CA):Thawte
Effective date:Sunday, September 18, 2011
Expiration date:Thursday, November 7, 2013
Digital DNA
File packed:No
.NET CLR:No
More details

ResourcesPrograms

The following programs will install this file
Evernote Corp.
4% remove
Evernote is a suite of software and services designed for notetaking and archiving. A "note" can be a piece of formatted text, a full webpage or webpage excerpt, a photograph, a voice memo, or a handwritten "ink" note. Notes can also have file attachments. Web clipping support is installed by default on the Internet Explorer and Safari browsers when the Evernote software is installed under Windows. The Evernote email-clipper is automat...

BehaviorsBehaviors

User start menu folder
Shortcut pointer placed in '%appdata%\Microsoft\Windows\Start Menu'
  • Shortcut to 'evernoteclipper.exe'
Network connections
  • [TCP] www.evernote.com (204.154.94.81:443)

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.00014556%
    0.028634%
    Kernel CPU:0.00006200%
    0.013761%
    User CPU:0.00008356%
    0.014873%
    Kernel CPU time:250,850 ms/min
    100,923,805ms/min
    CPU cycles:71,586/sec
    17,470,203/sec
    Memory
    Private memory:10 MB
    21.59 MB
    Private (maximum):13.55 MB
    Private (minimum):3.49 MB
    Non-paged memory:10 MB
    21.59 MB
    Virtual memory:97.45 MB
    140.96 MB
    Virtual memory (peak):104.57 MB
    169.69 MB
    Working set:11.43 MB
    18.61 MB
    Working set (peak):15.17 MB
    37.95 MB
    Page faults:19,724/min
    2,039/min
    I/O
    I/O read transfer:36 Bytes/sec
    1.02 MB/min
    I/O read operations:1/sec
    343/min
    I/O write transfer:0 Bytes/sec
    274.99 KB/min
    I/O write operations:1/sec
    227/min
    I/O other transfer:2 Bytes/sec
    448.09 KB/min
    I/O other operations:1/sec
    1,671/min
    Resource allocations
    Threads:5
    12
    Handles:170
    600
    GUI GDI count:80
    103
    GUI GDI peak:86
    142
    GUI USER count:17
    49
    GUI USER peak:24
    71

    BehaviorsProcess properties

    Integrety level:Undefined
    Platform:64-bit
    Command lines:
    • "C:\Program Files\evernote\evernote\evernoteclipper.exe"
    • "C:\users\user\appdata\local\apps\evernote\evernote\evernoteclipper.exe"
    Owner:User
    Parent processes:

    ResourcesThreads

    Averages
     
    EvernoteClipper.exe (main module)
    Total CPU:0.00058304%
    0.272967%
    Kernel CPU:0.00028711%
    0.107585%
    User CPU:0.00029593%
    0.165382%
    CPU cycles:54,519/sec
    5,741,424/sec
    Context switches:1/sec
    79/sec
    Memory:1.06 MB
    1.16 MB
    ntdll.dll
    Total CPU:0.00002222%
    Kernel CPU:0.00001481%
    User CPU:0.00000741%
    CPU cycles:1,228/sec
    Memory:1.66 MB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Windows 7 Home Premium 41.67%
    Windows 8 Pro 14.58%
    Windows 8 10.42%
    Windows 7 Professional 10.42%
    Windows Vista Home Premium 8.33%
    Windows 8 Pro with Media Center 8.33%
    Windows 8.1 2.08%
    Windows 7 Ultimate 2.08%
    Microsoft Windows XP 2.08%

    Distribution by countryDistribution by country

    United States installs about 70.83% of Evernote®.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 23.73%
    Hewlett-Packard 22.03%
    Toshiba 20.34%
    ASUS 10.17%
    Acer 6.78%
    MSI 6.78%
    GIGABYTE 5.08%
    Lenovo 3.39%
    Samsung 1.69%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE