Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

3516 0.90%
3423 0.90%
3374 0.90%
22.0.1471.70 0.90%
21.0.1432.67 0.90%
1860 9.91%
1748 9.91%
1748 0.90%
1738 16.22%
1734 0.90%
1734 0.90%
1707 15.32%
17.0.1241.53 11.71%
1661 10.81%
1661 0.90%
1652 5.41%
1578 4.50%
1532 2.70%
1497 (1) 0.90%
1467 0.90%
1190 0.90%
1185 0.90%
1087 0.90%
1017 (1) 0.90%

Relationships

Child process
Related files

PE structurePE file structure

Show functions
Import table
advapi32.dll
OpenProcessToken, IsValidSid, GetSidSubAuthority, GetSidSubAuthorityCount, GetTokenInformation, DuplicateTokenEx, RegGetKeySecurity, CheckTokenMembership, AllocateAndInitializeSid, AccessCheck, GetNamedSecurityInfoW, AdjustTokenPrivileges, CryptGenKey, CryptDestroyKey, CryptAcquireContextW, BuildExplicitAccessWithNameW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegDisablePredefinedCache, RevertToSelf, SetTokenInformation, GetLengthSid, ConvertStringSidToSidW, SetThreadToken, CreateProcessAsUserW, CreateRestrictedToken, DuplicateToken, EqualSid, LookupPrivilegeValueW, CopySid, CreateWellKnownSid, GetSecurityInfo, SetEntriesInAclW, RegQueryValueExW, RegQueryInfoKeyW, RegEnumKeyExW, RegDeleteValueW, RegSetValueExW, RegNotifyChangeKeyValue, RegEnumValueW, GetTraceEnableLevel, GetTraceEnableFlags, GetTraceLoggerHandle, UnregisterTraceGuids, TraceEvent, RegisterTraceGuidsW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegOpenKeyExA, RegQueryValueExA, CryptReleaseContext, CryptDestroyHash, CryptSignHashW, CryptSetHashParam, CryptGetHashParam, CryptCreateHash, SetNamedSecurityInfoW, GetExplicitEntriesFromAclW, GetUserNameW, RegDeleteKeyW
comctl32.dll
InitCommonControlsEx
comdlg32.dll
PrintDlgW, PrintDlgExW, CommDlgExtendedError, GetSaveFileNameW, GetOpenFileNameW, ChooseColorW
crypt32.dll
CryptMsgGetParam, CertFindCertificateInStore, CertGetNameStringW, CertFreeCertificateContext, CertCloseStore, CryptMsgClose, CryptQueryObject, CertAddEncodedCertificateToStore, CertDuplicateCertificateContext, CryptDecodeObjectEx, CertFindExtension, CertCompareCertificateName, CertGetPublicKeyLength, CryptFindOIDInfo, CertAddCertificateContextToStore, CertOpenStore, CertAddSerializedElementToStore, CryptHashCertificate, CertRDNValueToStrW, CertFreeCertificateChainEngine, CertFreeCertificateChain, CertVerifyCertificateChainPolicy, CertGetCertificateChain, CertSetCertificateContextProperty, CertGetCertificateContextProperty, CertVerifyTimeValidity, CertGetIntendedKeyUsage, CryptAcquireCertificatePrivateKey, CertOpenSystemStoreW, CertCreateCertificateChainEngine, CryptProtectData, CryptUnprotectData, CertFindChainInStore, CryptSignAndEncodeCertificate, CryptExportPublicKeyInfoEx
cryptui.dll
CryptUIDlgCertMgr, CryptUIDlgViewCertificateW
dhcpcsvc.dll
DhcpCApiInitialize, DhcpRequestParams
gdi32.dll
CreatePen, GetCurrentObject, GetStretchBltMode, StrokeAndFillPath, ExtCreatePen, GetICMProfileW, SwapBuffers, ChoosePixelFormat, SetPixelFormat, SetMiterLimit, StrokePath, GetTextColor, GetRgnBox, EqualRgn, ExcludeClipRect, RectInRegion, GetDIBits, PatBlt, SetICMMode, GetRegionData, Rectangle, SetAbortProc, StartDocW, CreateDCW, EndDoc, CancelDC, StartPage, SaveDC, RestoreDC, EndPage, GetEnhMetaFileHeader, GdiComment, GetEnhMetaFileBits, PlayEnhMetaFile, SetEnhMetaFileBits, GetEnhMetaFileW, ExtEscape, PlayEnhMetaFileRecord, GetCharWidthI, GetStockObject, EnumFontFamiliesW, CreatePolygonRgn, StretchDIBits, SetRectRgn, CombineRgn, SetDIBits, SetDIBitsToDevice, CreateFontW, GetTextExtentPoint32W, SetMapMode, GetDeviceCaps, CreateRectRgn, CreateRectRgnIndirect, PathToRegion, SelectClipRgn, SetPolyFillMode, BeginPath, PolyBezier, AbortPath, EndPath, SetStretchBltMode, SetBrushOrgEx, SetArcDirection, SetDCBrushColor, SetDCPenColor, SetROP2, GdiAlphaBlend, GetObjectW, GetCharABCWidthsW, EnumFontFamiliesExW, GetFontUnicodeRanges, GetTextFaceW, GetTextExtentPointI, SetGraphicsMode, SetBkMode, SetTextAlign, CreateDIBSection, ExtTextOutW, GdiFlush, AddFontMemResourceEx, GetGlyphIndicesW, RemoveFontMemResourceEx, GetOutlineTextMetricsW, GetTextMetricsW, GetFontData, GetGlyphOutlineW, CreateFontIndirectW, CreateCompatibleBitmap, StretchBlt, CreateBitmap, BitBlt, GetWorldTransform, ModifyWorldTransform, SetWorldTransform, DeleteDC, GetPixel, CreateCompatibleDC, CreateEnhMetaFileW, CloseEnhMetaFile, EnumEnhMetaFile, DeleteEnhMetaFile, SetBkColor, SetTextColor, GetBkColor, CreateSolidBrush, DeleteObject, SelectObject
imm32.dll
ImmReleaseContext, ImmGetConversionStatus, ImmSetOpenStatus, ImmAssociateContextEx, ImmDisableTextFrameService, ImmGetContext, ImmGetCompositionStringW, ImmGetIMEFileNameW, ImmNotifyIME, ImmSetCompositionWindow, ImmSetCandidateWindow, ImmSetConversionStatus
iphlpapi.dll
NotifyAddrChange, GetAdaptersAddresses, CancelIPChangeNotify
kernel32.dll
GetCurrentThreadId, InterlockedCompareExchange, GetFileAttributesA, GetCurrentProcessId, GetModuleFileNameA, WaitForSingleObject, SuspendThread, GetCurrentThread, FormatMessageA, LocalFree, WriteFile, IsBadReadPtr, CreateFileMappingA, MapViewOfFile, UnmapViewOfFile, ReadProcessMemory, GetLocalTime, GetTempPathA, CreateDirectoryA, CreateFileA, DebugActiveProcess, SetEvent, WaitForDebugEvent, GetThreadContext, ContinueDebugEvent, InitializeCriticalSection, VirtualAlloc, VirtualProtect, DeleteCriticalSection, VirtualFree, EnterCriticalSection, LeaveCriticalSection, RaiseException, GetModuleFileNameW, LoadLibraryW, CloseHandle, GetCurrentProcess, WideCharToMultiByte, OpenProcess, MultiByteToWideChar, LocalAlloc, GetVersionExA, GetCommandLineW, ExitProcess, SetUnhandledExceptionFilter, FindFirstFileW, CreateFileW, ReadFile, DeleteFileW, FindNextFileW, FindClose, RemoveDirectoryW, GetTempPathW, CreateEventW, WaitForMultipleObjects, GlobalAlloc, GlobalFree, CreateMutexW, OpenMutexW, Sleep, GetFileSize, LoadLibraryExW, HeapAlloc, GetProcessHeap, HeapFree, HeapReAlloc, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetLastError, CreateEventA, FreeLibrary, GetProcAddress, GetSystemDirectoryW, LoadLibraryA, lstrcmpiA, GetSystemDirectoryA, DllMain
ole32.dll
CoTaskMemFree, CLSIDFromString, OleInitialize, OleUninitialize, RegisterDragDrop, CoCreateInstance, CoSetProxyBlanket, DoDragDrop, PropVariantClear, RevokeDragDrop, StringFromGUID2, CoCreateGuid, CoInitializeEx, CoUninitialize, CoTaskMemAlloc, CoTaskMemRealloc, OleDuplicateData, ReleaseStgMedium
oleacc.dll
LresultFromObject, AccessibleObjectFromWindow, CreateStdAccessibleObject
psapi.dll
GetModuleFileNameExA, EnumProcesses, EnumProcessModules, GetMappedFileNameW, QueryWorkingSet, GetProcessMemoryInfo
rpcrt4.dll
UuidToStringW, UuidCreateSequential, RpcStringFreeW
secur32.dll
DeleteSecurityContext, FreeCredentialsHandle, QuerySecurityPackageInfoW, AcquireCredentialsHandleW, InitializeSecurityContextA, FreeContextBuffer, AcquireCredentialsHandleA, CompleteAuthToken, InitializeSecurityContextW
setupapi.dll
SetupDiSetDeviceInstallParamsW, SetupDiBuildDriverInfoList, SetupDiEnumDeviceInfo, SetupDiGetDeviceRegistryPropertyW, SetupDiDestroyDeviceInfoList, SetupDiGetClassDevsW, SetupDiGetDeviceInterfaceDetailW, SetupDiGetDeviceInstallParamsW, SetupDiEnumDriverInfoW, SetupDiDestroyDriverInfoList, SetupDiEnumDeviceInterfaces
shell32.dll
SHGetPathFromIDListW, SHGetSpecialFolderLocation, ShellExecuteExW, ShellExecuteW, ShellExecuteA, ShellExecuteExA
shlwapi.dll
SHGetValueA, SHDeleteKeyW, PathFindFileNameW, PathRemoveExtensionW, PathFindExtensionW, UrlCreateFromPathA, PathFileExistsW, PathGetCharTypeW, PathIsUNCW, UrlCreateFromPathW, SHStrDupW, PathFileExistsA, PathIsUNCA
urlmon.dll
CoInternetCreateSecurityManager
user32.dll
LoadIconA, SendMessageA, DialogBoxIndirectParamA, EndDialog, GetWindowThreadProcessId, FindWindowA, wvsprintfA, MessageBoxA, wsprintfA, EnumWindows, MessageBeep, SetForegroundWindow, SetActiveWindow, FlashWindow, GetClassNameA, GetWindowInfo
userenv.dll
DestroyEnvironmentBlock, CreateEnvironmentBlock
usp10.dll
ScriptStringAnalyse, ScriptCPtoX, ScriptXtoCP, ScriptStringOut, ScriptItemize, ScriptLayout, ScriptPlace, ScriptStringFree, ScriptGetFontProperties, ScriptFreeCache, ScriptJustify, ScriptShape
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
winhttp.dll
WinHttpCloseHandle, WinHttpGetIEProxyConfigForCurrentUser, WinHttpGetProxyForUrl, WinHttpOpen, WinHttpSetTimeouts
winmm.dll
timeSetEvent, waveOutPause, waveOutPrepareHeader, waveOutRestart, waveOutOpen, waveOutWrite, waveOutClose, waveOutReset, timeKillEvent, timeGetTime, timeBeginPeriod, timeEndPeriod, waveInGetDevCapsW, waveInOpen, waveOutGetNumDevs, waveInGetNumDevs, waveInClose, waveInReset, waveInStart, waveInAddBuffer, waveInUnprepareHeader, waveInPrepareHeader, waveInMessage, waveOutUnprepareHeader
winspool.drv
DocumentPropertiesW, EnumPrintersW, ClosePrinter, OpenPrinterW, GetPrinterW
wintrust.dll
WinVerifyTrust
ws2_32.dll
WSAIoctl, WSALookupServiceBeginW, WSALookupServiceEnd, WSACreateEvent, WSACloseEvent, WSARecv, WSALookupServiceNextW, WSAEventSelect, WSASend, WSAResetEvent, WSAGetOverlappedResult, WSAEnumNetworkEvents, freeaddrinfo, getaddrinfo, WSARecvFrom, WSASendTo, WSASocketW, WSCEnumProtocols, WSAWaitForMultipleEvents, WSASetEvent
wtsapi32.dll
WTSUnRegisterSessionNotification, WTSRegisterSessionNotification

Opera.exe

Opera Internet Browser by Opera Software ASA (Signed)

Remove Opera.exe
Version:   17.0.1241.53
MD5:   18cb59e55056046683e0d46ca26202bc
SHA1:   3373249ca0104dad50ddadf8d88acfae46a2acc0

What is Opera.exe?

Opera is a web browser and Internet suite developed by Opera Software. The browser handles common Internet-related tasks such as displaying web sites, sending and receiving e-mail messages, managing contacts, chatting on IRC, downloading files via BitTorrent, and reading web feeds. Opera is offered free of charge for personal computers and mobile phones.

Overview

opera.exe executes as a process with the local user's privileges. It is set to be run when the PC boots and the user logs into Windows (added to the Run registry key for the current user). It has been configured with a firewall exception which allows both inbound and outbound network communication without being blocked. The file is digitally signed by Opera Software ASA which was issued by the VeriSign certificate authority (CA).

DetailsDetails

File name:opera.exe
Publisher:Opera Software
Product name:Opera Internet Browser
Typical file path:C:\Program Files\opera\opera.exe
File version:17.0.1241.53
Size:40.28 MB (42,239,328 bytes)
Build date:10/19/2013 5:52 AM
Certificate
Issued to:Opera Software ASA
Authority (CA):VeriSign
Effective date:Tuesday, January 26, 2010
Expiration date:Monday, January 28, 2013
Digital DNA
File packed:No
.NET CLR:No
More details

BehaviorsBehaviors

Shell open commands
  • snews
  • nntp
  • news
  • mailto
  • https
  • http
Scheduled tasks
  • The task '{9581A5A4-9522-49D7-A7AE-3456CB754CCE}' runs on registration in the path '\{9581A5A4-9522-49D7-A7AE-3456CB754CCE}'
  • The task '{AFF8EFBA-D690-4EE9-8DBF-E25BFAB1D342}' runs on registration in the path '\{AFF8EFBA-D690-4EE9-8DBF-E25BFAB1D342}'
  • The task '{A8A3302D-90DF-46C9-AC23-5A518CB90275}' runs on registration in the path '\{A8A3302D-90DF-46C9-AC23-5A518CB90275}'
  • Entry path '\{DBC2D001-9068-4F6E-AECD-4B166D8DEC16}'
  • Entry path '\{B9799E4C-1D78-4825-9D4F-83E3FC192B02}'
  • Entry path '\{653B8D91-2FFC-4E84-AC21-E0828F9F6FE8}'
  • Entry path '\{462715D9-C7F9-4314-8AD7-9AC63086A59B}'
  • Entry path '\{C9323499-B412-4A75-9387-C3B96102DEA0}'
Windows firewall allowed programs
Exceptions allow programs to access to the Internet through an outbound connections
  • Firewall exception for 'C:\Program Files\Opera Next\opera.exe'
  • Firewall exception for 'C:\Program Files\Opera\opera.exe'
Startup files (user) run
Runs under the registry key 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
  • 'Opera Internet Browser' → C:\Program Files\Opera x64\Opera.exe
Network connections
Access through an approved Windows firewall exception
  • [TCP] kul06s06-in-f20.1e100.net (173.194.126.116:80)

  • ResourcesResource utilization

    (Note: statistics below are averages based on a minimum sample size of 200 unique participants)
    Averages
     
    CPU
    Total CPU:0.07684318%
    0.028634%
    Kernel CPU:0.04968773%
    0.013761%
    User CPU:0.02715545%
    0.014873%
    Kernel CPU time:2,913 ms/min
    100,923,805ms/min
    Context switches:81/sec
    284/sec
    Memory
    Private memory:49.01 MB
    21.59 MB
    Private (maximum):58.08 MB
    Private (minimum):41.39 MB
    Non-paged memory:49.01 MB
    21.59 MB
    Virtual memory:223.07 MB
    140.96 MB
    Virtual memory (peak):237.81 MB
    169.69 MB
    Working set:46.39 MB
    18.61 MB
    Working set (peak):64.17 MB
    37.95 MB
    Resource allocations
    Threads:13
    12
    Handles:260
    600
    GUI GDI count:67
    103
    GUI GDI peak:71
    142
    GUI USER count:9
    49
    GUI USER peak:14
    71

    BehaviorsProcess properties

    Integrety level:Untrusted
    Platform:64-bit
    Command lines:
    • "C:\Program Files\opera\17.0.1241.53_0\opera.exe" --type=renderer --lang=en-gb --disable-client-side-phishing-detection --crash-reporter-pid=4912 --channel="4900.18.2098838043\1048216234" /prefetcC:673131151
    • "C:\Program Files\opera\17.0.1241.53_0\opera.exe" --type=renderer --lang=en-gb --disable-client-side-phishing-detection --crash-reporter-pid=4912 --channel="4900.17.771179818\1831487752" /prefetcC:673131151
    • "C:\Program Files\opera\17.0.1241.53_0\opera.exe" --type=renderer --lang=en-gb --disable-client-side-phishing-detection --crash-reporter-pid=4912 --channel="4900.8.2104076004\2130164435" /prefetcC:673131151
    • "C:\Program Files\opera\17.0.1241.53_0\opera.exe" -noautoupdate --ran-launcher httC://go.microsoft.com/fwlink/?linkid=219472&clcid=0x409
    • "C:\Program Files\opera\17.0.1241.53_0\opera.exe" --type=renderer --lang=en-gb --extension-process --disable-client-side-phishing-detection --crash-reporter-pid=4912 --channel="4900.1.1133256860\1383838904" /prefetcC:673131151
    • "C:\Program Files\opera\17.0.1241.53_0\opera.exe" --type=renderer --lang=en-gb --disable-client-side-phishing-detection --crash-reporter-pid=4912 --channel="4900.15.1144531432\2072663245" /prefetcC:673131151
    • "C:\Program Files\opera\17.0.1241.53_0\opera.exe" --type=renderer --lang=en-gb --extension-process --disable-client-side-phishing-detection --crash-reporter-pid=4912 --channel="4900.0.868155680\1749624525" /prefetcC:673131151
    • (22 more)
    Owner:User
    Parent process:opera.exe (Opera Internet Browser by Opera Software ASA)

    ResourcesThreads

    Averages
     
    npswf32_11_9_900_117.dll (Shockwave Flash by Adobe Systems)
    Total CPU:0.83486214%
    0.272967%
    Kernel CPU:0.03264883%
    0.107585%
    User CPU:0.80221331%
    0.165382%
    CPU cycles:28,085,181/sec
    5,741,424/sec
    Context switches:53/sec
    79/sec
    Memory:16.46 MB
    1.16 MB
    opera.exe (main module)
    Total CPU:0.43882394%
    Kernel CPU:0.09419966%
    User CPU:0.34462428%
    CPU cycles:12,612,759/sec
    Context switches:36/sec
    Memory:40.63 MB
    ntdll.dll
    Total CPU:0.11174694%
    Kernel CPU:0.07310192%
    User CPU:0.03864502%
    CPU cycles:3,492,069/sec
    Context switches:82/sec
    Memory:1.23 MB
    wow64.dll
    Total CPU:0.02590977%
    Kernel CPU:0.00987331%
    User CPU:0.01603646%
    CPU cycles:728,448/sec
    Context switches:2/sec
    Memory:292 KB

    Common loaded modules

    These are modules that are typiclaly loaded within the context of this process.

    Windows OS versionsDistribution by Windows OS

    OS versiondistribution
    Microsoft Windows XP 44.14%
    Windows 7 Ultimate 16.22%
    Windows 8.1 Pro 11.71%
    Windows 7 Home Premium 8.11%
    Windows 7 Home Basic 5.41%
    Windows 7 Professional 5.41%
    Windows 8 Pro 2.70%
    Windows Se7en Titan 1.80%
    Windows 8 Pro with Media Center 0.90%
    Windows 8 0.90%
    Windows 7 Enterprise 0.90%
    Windows Vista Home Premium 0.90%
    Windows Vista Ultimate 0.90%

    Distribution by countryDistribution by country

    India installs about 15.89% of Opera Internet Browser.

    OEM distributionDistribution by PC manufacturer

    PC Manufacturerdistribution
    Dell 24.53%
    Sony 22.64%
    ASUS 13.21%
    Lenovo 9.43%
    Toshiba 7.55%
    Intel 5.66%
    American Megatrends 4.72%
    GIGABYTE 3.77%
    Acer 3.77%
    Hewlett-Packard 3.77%
    Samsung 0.94%
    Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

    Download it for FREE