picpick.exe

PicPick

Wiziple software

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘PicPick Start’.
Publisher:
NTeWORKS  (signed by Wiziple software)

Product:
PicPick

Version:
3.1.8.0

MD5:
4164c20150e1e07cdb98a33503c34879

SHA-1:
27c406fa68e25e17fbfa09b9e394c77ad90fe7d6

SHA-256:
7d67f2f8456bd9adb5668d6f92533cd563fc93c97d70576f8aebd67fc2df6b10

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
11/23/2024 10:20:43 PM UTC  (today)

File size:
9.9 MB (10,413,184 bytes)

Product version:
1.0.0.0

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\picpick\picpick.exe

Digital Signature
Authority:
Thawte, Inc.

Valid from:
6/1/2012 9:00:00 AM

Valid to:
6/2/2014 8:59:59 AM

Subject:
CN=Wiziple software, OU=Dev Team, O=Wiziple software, L=Jungnang-gu, S=Seoul, C=KR

Issuer:
CN=Thawte Code Signing CA - G2, O="Thawte, Inc.", C=US

Serial number:
20C0DB1FF9E34B041EEC3E45D599B283

File PE Metadata
Compilation timestamp:
9/10/2012 10:23:40 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
196608:wWkYw1b/faNExx2fQ6kUxsZPJhB05nnRs58YhNQpQ7MbLALYLsLVLI:JkYEzUxqPJhB05nRs58YhNQC70LALYLj

Entry address:
0x6EA9A0

Entry point:
55, 8B, EC, B9, 0E, 00, 00, 00, 6A, 00, 6A, 00, 49, 75, F9, 53, 56, 57, B8, 38, AE, AD, 00, E8, 54, 16, 92, FF, 33, C0, 55, 68, 5A, AE, AE, 00, 64, FF, 30, 64, 89, 20, 8D, 55, EC, B8, 01, 00, 00, 00, E8, 81, 9D, 91, FF, 8B, 45, EC, BA, 78, AE, AE, 00, E8, 9C, DE, 91, FF, 75, 0A, E8, 05, C4, 91, FF, E9, F6, 03, 00, 00, 8D, 55, E8, B8, 01, 00, 00, 00, E8, 5B, 9D, 91, FF, 8B, 45, E8, BA, A4, AE, AE, 00, E8, 76, DE, 91, FF, 75, 0A, E8, DF, C3, 91, FF, E9, D0, 03, 00, 00, 8D, 55, E4, B8, 01, 00, 00, 00, E8, 35...
 
[+]

Entropy:
6.4273

Developed / compiled with:
Microsoft Visual C++

Code size:
6.9 MB (7,248,896 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
PicPick Start

Command:
C:\Program Files\picpick\picpick.exe \startup


Scan picpick.exe - Powered by Reason Core Security