update_notifier.exe threat report

MD5 e246b59d87ac22ba11d0300f66c206ac
Latest seen 2026-03-02 23:00:53 (2 months ago)
First seen 2026-03-02 23:00:52 (2 months ago)
Size 3 MB

GridinSoft Anti-Malware detection

Detected by GridinSoft before you download

The current ThreatInfo record shows this exact file hash detected as Possible Threat. Download GridinSoft Anti-Malware to scan the device, confirm whether this file is present, and remove the detected object if it is found.

Detection name
Possible Threat
Recommended action
Scan and remove
Last analysis
2026-03-02 23:00:53 (2 months ago)
File hash
e246b59d87ac22ba11d0300f66c206ac
Download Anti-Malware

Why it matters

Why GridinSoft flags this file

Detection

GridinSoft identifies the sample as Possible Threat.

Timeline

First seen 2026-03-02 23:00:52 (2 months ago); latest analysis 2026-03-02 23:00:53 (2 months ago).

Publisher context

Company metadata: Vivaldi Technologies AS. Product metadata: Vivaldi update notifier.

Observed locations

ThreatInfo has seen this file in user or system paths listed below. Unexpected locations increase the need for local verification.

Recommended action

What to do next

  1. Compare the MD5 above with the file found on the device.
  2. Check whether the file appears in the observed locations or under one of the alternate names.
  3. Run GridinSoft Anti-Malware to confirm the detection and remove the file if it is present.

update_notifier.exe is a Windows file recorded in the ThreatInfo database. It is associated with Vivaldi update notifier. The reported company name is Vivaldi Technologies AS. The current detection status is Possible Threat, based on the latest analysis from 2026-03-02 23:00:53 (2 months ago).

If update_notifier.exe appears on your computer unexpectedly, treat it as suspicious. Check its location, digital signature, and recent system changes before allowing it to run. A full anti-malware scan is recommended when this file is detected as Possible Threat.

Product Name: Vivaldi update notifier
Company Name: Vivaldi Technologies AS
MD5: e246b59d87ac22ba11d0300f66c206ac
Size: 3 MB
First Published: 2026-03-02 23:00:52 (2 months ago)
Latest Published: 2026-03-02 23:00:53 (2 months ago)
Status: Possible Threat (on last analysis)
Analysis Date: 2026-03-02 23:00:53 (2 months ago)
update_notifier.exe detection screenshot

The screenshot is a visual record of a GridinSoft Anti-Malware detection for this sample. Use the hash and metadata above as the primary identifiers when comparing the file on your system.

%localappdata%\vivaldi
%localappdata%\vivaldi

ThreatInfo has observed update_notifier.exe in the locations listed above. Files found in temporary folders, user profile folders, startup locations, or unusual application directories should be reviewed more carefully than files installed under a known program directory.

100.0%

The strongest geographic signal for this file is Egypt with 100.0% of observed hits. Geographic distribution can help identify targeted campaigns, regional software bundles, or where a file is most commonly reported.

Windows 10 100.0%

The most common operating system signal for update_notifier.exe is Windows 10 with 100.0% of observed hits. If your system differs from the common profile, check whether the file was introduced by a specific installer, archive, or removable device.

update_notifier.exe is identified as pe for 64 systems. The subsystem is Windows GUI. PE header values are useful for triage, especially when they do not match the expected publisher, product, or release timeline.

Subsystem: Windows GUI
PE Type: pe
OS Bitness: 64
Image Base: 0x0000000140000000
Entry Address: 0x002387d0

PE Sections:

Name Size of data MD5
.text 2907136 e3fe4ec93e9912564c1aeb5f0fb8bb60
.rdata 789504 ddd915c3179f66ab2a203ff892109f53
.data 60928 acf559005b1d8fa6dc765451f0655e6c
.pdata 85504 d84cbf6bf079c72dabc8fa28715ba396
.fptable 512 bf619eac0cdf3f68d496ea9344137e8b
.tls 1024 5f0d5065071c6cd76233b69e3e4aadbf
LZMADEC 4608 05e9eab8428a551a281ab278073669fa
_RDATA 512 573fc4eccf286b70af39d2906284f6b4
malloc_h 512 dcbcaf89c8a42c2678d83c023d848b48
.rsrc 267264 33cf648fd41aa9216c35e8740b97c24d
.reloc 32256 6c6fd97aa55a72100def69c6b7e69adf

PE section names and hashes can reveal packing, injected resources, or unusual build artifacts. Sections with uncommon names, very large raw data, or hashes that differ from a trusted copy deserve additional review.

More information: