Home Malware Programs Potentially Unwanted Programs (PUPs) Picexa Viewer

Picexa Viewer

Posted: April 2, 2015

Threat Metric

Ranking: 5,909
Threat Level: 1/10
Infected PCs: 77,477
First Seen: March 27, 2015
Last Seen: March 8, 2025
OS(es) Affected: Windows

Picexa Viewer is a PUP (Potentially Unwanted Program) that is created by Taiwan Shui Mu Chih Ching Technology Limited. The same company is for creating other applications such as Winzipper, Qone8.com and also the Omiga Plus. At first glance, Picexa Viewer may seem like a useful application, but in reality, computer security experts advise users to think twice before installation. However, in case your web browser suddenly starts displaying annoying advertisements by Picexa Viewer, then it was probably installed unintentionally. Accidentally installing applications typically occurs when users engage in freeware downloads. Once on your computer, Picexa Viewer starts collecting information on your browsing activities and display intrusive online advertisements. Computer security experts warn users to think twice if the functionality Picexa Viewer provides has any actual value.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\st367C.tmp\Picexa.exe File name: Picexa.exe
Size: 426.68 KB (426680 bytes)
MD5: 509a3cd888f8bf2f453bd677b0bdcc4b
Detection count: 475
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Local\Temp\st367C.tmp\Picexa.exe
Group: Malware file
Last Updated: January 21, 2024
%PROGRAMFILES%\Picexa\uninstall.exe File name: uninstall.exe
Size: 1.58 MB (1580696 bytes)
MD5: 25ee42792f9354f9e0992db3a21af593
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Picexa
Group: Malware file
Last Updated: February 11, 2016
C:\WINDOWS\System32\MRT\3AC662F4-BBD5-4771-B2A0-164912094D5D\FilesStash\E0A048C7-FDF1-3CF0-C73B-9AF6BD251A1B File name: E0A048C7-FDF1-3CF0-C73B-9AF6BD251A1B
Size: 729.22 KB (729224 bytes)
MD5: 328fcb1da2434e2ff20b69f35c999326
Detection count: 33
Path: C:\WINDOWS\System32\MRT\3AC662F4-BBD5-4771-B2A0-164912094D5D\FilesStash\E0A048C7-FDF1-3CF0-C73B-9AF6BD251A1B
Group: Malware file
Last Updated: December 9, 2022
C:\Windows\SmartFix\AdwCleaner\quarantine\files\aurostozyificalsbajonovwgtkcivnu\itools\webtool.exe File name: webtool.exe
Size: 3.66 MB (3661312 bytes)
MD5: b4d098f84ed0eeda265b677d4705c0c1
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: C:\Windows\SmartFix\AdwCleaner\quarantine\files\aurostozyificalsbajonovwgtkcivnu\itools\webtool.exe
Group: Malware file
Last Updated: May 14, 2021
C:\Users\<username>\Desktop\RESTORED\2018-03-25_10-58-09\dup.exe File name: dup.exe
Size: 441.99 KB (441992 bytes)
MD5: 49ffc5515da206af3351a6e649a6720f
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\RESTORED\2018-03-25_10-58-09\dup.exe
Group: Malware file
Last Updated: April 5, 2022
%PROGRAMFILES%\Picexa\ucp~213440\RunTools.exe File name: RunTools.exe
Size: 110.59 KB (110592 bytes)
MD5: c7de2b11562aa1db7b079d0177edebc1
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Picexa\ucp~213440
Group: Malware file
Last Updated: December 6, 2019
%PROGRAMFILES%\Picexa\PicexaSvc.exe File name: PicexaSvc.exe
Size: 730.24 KB (730248 bytes)
MD5: ff84636054efe423acc7f5787658b49f
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Picexa
Group: Malware file
Last Updated: February 11, 2016

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathPicexa.lnkHKEY..\..\..\..{RegistryKeys}SOFTWARE\Classes\PicexaViewer.bmpSOFTWARE\Classes\PicexaViewer.gifSOFTWARE\Classes\PicexaViewer.icoSOFTWARE\Classes\PicexaViewer.jpegSOFTWARE\Classes\PicexaViewer.jpgSOFTWARE\Classes\PicexaViewer.pngSOFTWARE\Classes\PicexaViewer.tifSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.bmp\OpenWithProgids\PicexaViewer.bmpSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.gif\OpenWithProgids\PicexaViewer.gifSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ico\OpenWithProgids\PicexaViewer.icoSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpe\OpenWithProgids\PicexaViewer.jpgSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpeg\OpenWithProgids\PicexaViewer.jpgSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\OpenWithProgids\PicexaViewer.jpgSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.jpg\UserChoice\PicexaViewer.pngSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.png\OpenWithProgids\PicexaViewer.pngSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tif\OpenWithProgids\PicexaViewer.tifSoftware\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tiff\OpenWithProgids\PicexaViewer.tifSOFTWARE\PicexaSOFTWARE\PicexaSvcSoftware\V9\Picexa ViewerSOFTWARE\Wow6432Node\PicexaSOFTWARE\Wow6432Node\PicexaSvcSYSTEM\ControlSet001\services\eventlog\Application\PicexaServiceSYSTEM\ControlSet001\services\PicexaServiceSYSTEM\ControlSet002\services\eventlog\Application\PicexaServiceSYSTEM\ControlSet002\services\PicexaServiceSYSTEM\CurrentControlSet\services\eventlog\Application\PicexaServiceSYSTEM\CurrentControlSet\services\PicexaServiceHKEY_LOCAL_MACHINE\Software\[APPLICATION]\Microsoft\Windows\CurrentVersion\Uninstall..{Uninstaller}Picexa

Additional Information

The following directories were created:
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Picexa%ALLUSERSPROFILE%\Start Menu\Programs\Picexa%APPDATA%\Picexa Viewer%PROGRAMFILES%\Picexa%PROGRAMFILES(x86)%\Picexa
Loading...