Home Malware Programs Potentially Unwanted Programs (PUPs) Picexa Viewer

Picexa Viewer

Posted: April 2, 2015

Threat Metric

Ranking: 4,316
Threat Level: 1/10
Infected PCs: 76,671
First Seen: March 27, 2015
Last Seen: October 17, 2023
OS(es) Affected: Windows

Picexa Viewer is a PUP (Potentially Unwanted Program) that is created by Taiwan Shui Mu Chih Ching Technology Limited. The same company is for creating other applications such as Winzipper, Qone8.com and also the Omiga Plus. At first glance, Picexa Viewer may seem like a useful application, but in reality, computer security experts advise users to think twice before installation. However, in case your web browser suddenly starts displaying annoying advertisements by Picexa Viewer, then it was probably installed unintentionally. Accidentally installing applications typically occurs when users engage in freeware downloads. Once on your computer, Picexa Viewer starts collecting information on your browsing activities and display intrusive online advertisements. Computer security experts warn users to think twice if the functionality Picexa Viewer provides has any actual value.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\st7DAA.tmp\Picexa.exe File name: Picexa.exe
Size: 1.38 MB (1384072 bytes)
MD5: cbe24a05283c72d5d19376b07c529913
Detection count: 3,122
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\st7DAA.tmp\Picexa.exe
Group: Malware file
Last Updated: July 21, 2023
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\st7DAA.tmp\PicexaSvc.exe File name: PicexaSvc.exe
Size: 722.4 KB (722400 bytes)
MD5: 5906aa054c3fe8760721c353a359c2bb
Detection count: 1,504
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\st7DAA.tmp\PicexaSvc.exe
Group: Malware file
Last Updated: April 4, 2023
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\st7DAA.tmp\dup.exe File name: dup.exe
Size: 407.68 KB (407688 bytes)
MD5: 0355ad3689b802e4fe61553c02d90d5b
Detection count: 717
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\st7DAA.tmp\dup.exe
Group: Malware file
Last Updated: July 4, 2023
C:\Users\<username>\AppData\Local\Temp\stE12B.tmp\dup.exe File name: dup.exe
Size: 409.77 KB (409776 bytes)
MD5: d462e732bb8d1dc770f8b60df40d7259
Detection count: 660
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\stE12B.tmp\dup.exe
Group: Malware file
Last Updated: April 4, 2023
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\~eqtmp29475780\PicexaSvc.exe File name: PicexaSvc.exe
Size: 731.78 KB (731784 bytes)
MD5: 7e15f72a2108137ced2e0ec1d17b6366
Detection count: 581
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\~eqtmp29475780\PicexaSvc.exe
Group: Malware file
Last Updated: July 21, 2023
C:\Users\<username>\AppData\Local\Temp\~eqtmp372109\PicexaSvc.exe File name: PicexaSvc.exe
Size: 730.24 KB (730248 bytes)
MD5: 723d70ba249750fbd05a9906652a151d
Detection count: 548
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\~eqtmp372109\PicexaSvc.exe
Group: Malware file
Last Updated: April 4, 2023
%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\st367C.tmp\Picexa.exe File name: Picexa.exe
Size: 426.68 KB (426680 bytes)
MD5: 509a3cd888f8bf2f453bd677b0bdcc4b
Detection count: 473
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\st367C.tmp\Picexa.exe
Group: Malware file
Last Updated: July 12, 2023
C:\Users\<username>\AppData\Local\Temp\~eqtmp7676419\dup.exe File name: dup.exe
Size: 428.2 KB (428208 bytes)
MD5: bad183352a444bc831abc9966aa00fae
Detection count: 400
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\~eqtmp7676419\dup.exe
Group: Malware file
Last Updated: July 21, 2023
F:\dick E\Users\<username>\AppData\Local\Temp\st6011.tmp\PicexaSvc.exe File name: PicexaSvc.exe
Size: 725.64 KB (725640 bytes)
MD5: dbb19211e0f65c65c00596c77a4d8d72
Detection count: 333
File type: Executable File
Mime Type: unknown/exe
Path: F:\dick E\Users\<username>\AppData\Local\Temp\st6011.tmp\PicexaSvc.exe
Group: Malware file
Last Updated: July 4, 2023
C:\Users\<username>\AppData\Local\Temp\st5AFD.tmp\Picexa.exe File name: Picexa.exe
Size: 1.46 MB (1467032 bytes)
MD5: d4ef6182de78a2ad76dd8cefd079d2bb
Detection count: 197
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\st5AFD.tmp\Picexa.exe
Group: Malware file
Last Updated: February 27, 2023
E:\$Recycle.Bin\S-1-5-21-3703653240-753551165-3996674403-1000\$RJXB8W3.tmp\PicexaSvc.exe File name: PicexaSvc.exe
Size: 705.67 KB (705672 bytes)
MD5: 60ed9520474b558404bf3e180099f540
Detection count: 162
File type: Executable File
Mime Type: unknown/exe
Path: E:\$Recycle.Bin\S-1-5-21-3703653240-753551165-3996674403-1000\$RJXB8W3.tmp\PicexaSvc.exe
Group: Malware file
Last Updated: February 27, 2023
C:\Program Files (x86)\Picexa\PicexaSvc.exe File name: PicexaSvc.exe
Size: 729.22 KB (729224 bytes)
MD5: ba67505994535568b23c4e6c17f1c3b3
Detection count: 87
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Picexa\PicexaSvc.exe
Group: Malware file
Last Updated: February 27, 2023
C:\Users\<username>\AppData\Local\Temp\~eqtmp739179\PicexaSvc.exe File name: PicexaSvc.exe
Size: 778.88 KB (778888 bytes)
MD5: 3faec705404b7e7e183546ff6028f538
Detection count: 61
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\~eqtmp739179\PicexaSvc.exe
Group: Malware file
Last Updated: February 27, 2023
C:\Program Files\Picexa\PicexaSvc.exe File name: PicexaSvc.exe
Size: 706.18 KB (706184 bytes)
MD5: 2bdbaaffdfe13ee933960151c9468776
Detection count: 54
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Picexa\PicexaSvc.exe
Group: Malware file
Last Updated: May 30, 2022
C:\Program Files (x86)\Picexa\dup.exe File name: dup.exe
Size: 442.5 KB (442504 bytes)
MD5: 9e649c6b3b9498177974059bcbcb6dd9
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files (x86)\Picexa\dup.exe
Group: Malware file
Last Updated: November 15, 2021
C:\WINDOWS\System32\MRT\3AC662F4-BBD5-4771-B2A0-164912094D5D\FilesStash\E0A048C7-FDF1-3CF0-C73B-9AF6BD251A1B File name: E0A048C7-FDF1-3CF0-C73B-9AF6BD251A1B
Size: 729.22 KB (729224 bytes)
MD5: 328fcb1da2434e2ff20b69f35c999326
Detection count: 33
Path: C:\WINDOWS\System32\MRT\3AC662F4-BBD5-4771-B2A0-164912094D5D\FilesStash\E0A048C7-FDF1-3CF0-C73B-9AF6BD251A1B
Group: Malware file
Last Updated: December 9, 2022
%PROGRAMFILES%\Picexa\PicexaSvc.exe File name: PicexaSvc.exe
Size: 705.67 KB (705672 bytes)
MD5: 6a115e1aaf7dc03cfec38112c4d5178a
Detection count: 24
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Picexa
Group: Malware file
Last Updated: February 11, 2016
C:\Users\<username>\AppData\Local\Temp\st297C.tmp\dup.exe File name: dup.exe
Size: 454.79 KB (454792 bytes)
MD5: 5bc446762f65ce90b8ab012edad64156
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\st297C.tmp\dup.exe
Group: Malware file
Last Updated: May 30, 2022
C:\Windows\SmartFix\AdwCleaner\quarantine\files\aurostozyificalsbajonovwgtkcivnu\itools\webtool.exe File name: webtool.exe
Size: 3.66 MB (3661312 bytes)
MD5: b4d098f84ed0eeda265b677d4705c0c1
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\SmartFix\AdwCleaner\quarantine\files\aurostozyificalsbajonovwgtkcivnu\itools\webtool.exe
Group: Malware file
Last Updated: May 14, 2021
%PROGRAMFILES%\Picexa\PicexaSvc.exe File name: PicexaSvc.exe
Size: 730.24 KB (730248 bytes)
MD5: 8edd017fdc2ee4184c49234a6b694b9b
Detection count: 10
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Picexa
Group: Malware file
Last Updated: February 11, 2016
C:\Users\<username>\Desktop\RESTORED\2018-03-25_10-58-09\dup.exe File name: dup.exe
Size: 441.99 KB (441992 bytes)
MD5: 49ffc5515da206af3351a6e649a6720f
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\RESTORED\2018-03-25_10-58-09\dup.exe
Group: Malware file
Last Updated: April 5, 2022
%PROGRAMFILES%\Picexa\ucp~213440\RunTools.exe File name: RunTools.exe
Size: 110.59 KB (110592 bytes)
MD5: c7de2b11562aa1db7b079d0177edebc1
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Picexa\ucp~213440
Group: Malware file
Last Updated: December 6, 2019
%PROGRAMFILES%\Picexa\PicexaSvc.exe File name: PicexaSvc.exe
Size: 730.24 KB (730248 bytes)
MD5: ff84636054efe423acc7f5787658b49f
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Picexa
Group: Malware file
Last Updated: February 11, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathPicexa.lnkHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\PicexaViewer.bmpSOFTWARE\Classes\PicexaViewer.gifSOFTWARE\Classes\PicexaViewer.icoSOFTWARE\Classes\PicexaViewer.jpegSOFTWARE\Classes\PicexaViewer.jpgSOFTWARE\Classes\PicexaViewer.pngSOFTWARE\Classes\PicexaViewer.tifSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithProgids\PicexaViewer.bmpSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\OpenWithProgids\PicexaViewer.gifSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\OpenWithProgids\PicexaViewer.icoSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\OpenWithProgids\PicexaViewer.jpgSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\OpenWithProgids\PicexaViewer.jpgSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithProgids\PicexaViewer.jpgSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice\PicexaViewer.pngSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithProgids\PicexaViewer.pngSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\OpenWithProgids\PicexaViewer.tifSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\OpenWithProgids\PicexaViewer.tifSOFTWARE\PicexaSOFTWARE\PicexaSvcSoftware\V9\Picexa ViewerSOFTWARE\Wow6432Node\PicexaSOFTWARE\Wow6432Node\PicexaSvcSYSTEM\ControlSet001\services\eventlog\Application\PicexaServiceSYSTEM\ControlSet001\services\PicexaServiceSYSTEM\ControlSet002\services\eventlog\Application\PicexaServiceSYSTEM\ControlSet002\services\PicexaServiceSYSTEM\CurrentControlSet\services\eventlog\Application\PicexaServiceSYSTEM\CurrentControlSet\services\PicexaServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Picexa

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Picexa%ALLUSERSPROFILE%\Start Menu\Programs\Picexa%APPDATA%\Picexa Viewer%PROGRAMFILES%\Picexa%PROGRAMFILES(x86)%\Picexa
Loading...