BCWipeTM.exe

Jetico, Inc. BCWipe Task Manager

Jetico, Inc.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘BCWipeTM Startup’.
Publisher:
Jetico, Inc.  (signed and verified)

Product:
Jetico, Inc. BCWipe Task Manager

Description:
BCWipeTM

Version:
1.07.5

MD5:
a8bc796c08868c4f27379579f3256e9d

SHA-1:
a89521ca072009b8595ec90cb73ada33053bb502

SHA-256:
594e38a65d5d517f54f23c6592c50757e22f3c6e7f01a30ea73d62caa9c1a5a3

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 1:38:42 PM UTC  (today)

File size:
500.7 KB (512,752 bytes)

Product version:
1.07.5

Copyright:
Copyright © 2002-2007

Original file name:
BCWipeTM.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\jetico\bestcrypt\bcwipetm.exe

Digital Signature
Signed by:

Authority:
GeoTrust Inc

Valid from:
9/5/2006 12:35:29 PM

Valid to:
9/5/2009 12:35:29 PM

Subject:
CN="Jetico, Inc.", OU=GeoTrust Code Signing, OU=Sales, O="Jetico, Inc.", L=Espoo, S=Finland, C=FI

Issuer:
CN=GeoTrust TrustCenter CodeSigning CA I, O=GeoTrust Inc, OU=GeoTrust TrustCenter CodeSigning CA, C=US

Serial number:
71DA000100208F6CD781F7422B04

File PE Metadata
Compilation timestamp:
6/22/2007 9:28:12 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
12288:u2xj6beTqPShbPa8cylBXsoU/MnsJFBEMEI8MZ/pcitegS3/TJ+O5W+uEZoLBT9q:u2VdceGoiIgS3/TMO5W+YBq

Entry address:
0x3B3A4

Entry point:
E8, F2, 85, 00, 00, E9, 16, FE, FF, FF, 2D, A4, 03, 00, 00, 74, 22, 83, E8, 04, 74, 17, 83, E8, 0D, 74, 0C, 48, 74, 03, 33, C0, C3, B8, 04, 04, 00, 00, C3, B8, 12, 04, 00, 00, C3, B8, 04, 08, 00, 00, C3, B8, 11, 04, 00, 00, C3, 53, 55, 56, 57, BD, 01, 01, 00, 00, 8B, F0, 55, 33, FF, 8D, 5E, 1C, 57, 53, E8, 6B, D9, FF, FF, 89, 7E, 04, 89, 7E, 08, 89, 7E, 0C, 33, C0, 8D, 7E, 10, AB, AB, AB, B8, F8, 9F, 45, 00, 83, C4, 0C, 2B, C6, 8A, 0C, 18, 88, 0B, 43, 4D, 75, F7, 8D, 8E, 1D, 01, 00, 00, BE, 00, 01, 00, 00...
 
[+]

Entropy:
6.1064

Code size:
304 KB (311,296 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
BCWipeTM Startup

Command:
"C:\Program Files\jetico\bestcrypt\bcwipetm.exe" startup


Scan BCWipeTM.exe - Powered by Reason Core Security