GyStation.exe

Gyazo Station

Nota Inc.

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Gyazo’.
Publisher:
Nota Inc.  (signed and verified)

Product:
Gyazo Station

Version:
1.0.0.0

MD5:
dde16105862139906957070adc7f5b65

SHA-1:
0978005f4a068c1b7fc234647e30e8417e289b22

SHA-256:
25959206ebd3bf768a88d47a9aaf3b854d8bbb51e6abf1ae0b76d906c3c0b9d8

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/27/2024 9:26:08 AM UTC  (today)

File size:
2.9 MB (2,990,304 bytes)

Product version:
1.0.0.0

Copyright:
Copyright 2013 Nota Inc. All rights reserved.

Original file name:
GyStation.exe

File type:
Executable application (Win32 EXE)

Language:
Japanese (Japan)

Common path:
C:\Program Files\gyazo\gystation.exe

Digital Signature
Signed by:

Authority:
GlobalSign nv-sa

Valid from:
6/7/2013 5:52:39 AM

Valid to:
6/8/2014 5:52:39 AM

Subject:
E=contact@notaland.com, CN=Nota Inc., O=Nota Inc., C=US

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
11211CCA17AB4F243DDF50D9F9212A1F92EA

File PE Metadata
Compilation timestamp:
10/1/2013 6:36:58 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
49152:ZseXwUn5xKCrlu8E5hE9m5sQlhVkum0hcC+zf0T0ULDABoj9ghi1RebpyTIg9CbS:nXwAxKCrXE5hom5sQlhVkum6+YT0ULUw

Entry address:
0xF76DC

Entry point:
E8, E7, 69, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 8B, D0, 66, 8B, 08, 83, C0, 02, 66, 85, C9, 75, F5, 66, 8B, 4D, 0C, 83, E8, 02, 3B, C2, 74, 05, 66, 39, 08, 75, F4, 66, 39, 08, 74, 02, 33, C0, 5D, C3, 8B, FF, 55, 8B, EC, 56, 8B, 75, 14, 85, F6, 75, 04, 33, C0, EB, 61, 83, 7D, 08, 00, 75, 13, E8, 1C, 10, 00, 00, 6A, 16, 5E, 89, 30, E8, B3, 6B, 00, 00, 8B, C6, EB, 48, 83, 7D, 10, 00, 74, 16, 39, 75, 0C, 72, 11, 56, FF, 75, 10, FF, 75, 08, E8, 5B, 4B, 00, 00, 83, C4, 0C, EB, C7, FF, 75...
 
[+]

Entropy:
7.0430

Code size:
1.1 MB (1,160,192 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Gyazo

Command:
C:\Program Files\gyazo\gystation.exe


The file GyStation.exe has been discovered within the following programs.

Gyazo 1.0  by Toshiyuki Masui
gyazo.com
About 9% of users remove it
Gyazo 2.0.2  by Nota Inc. & Toshiyuki Masui
About 1% of users remove it
 
Powered by Should I Remove It?

Scan GyStation.exe - Powered by Reason Core Security