poplink.exe

121ポップリンク

NEC Personal Products, Ltd.

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘POPLINK’.
Publisher:
NEC Corporation, NEC Personal Products, Ltd.  (signed by NEC Personal Products, Ltd.)

Product:
121ポップリンク

Version:
2, 0, 29, 0

MD5:
2b84d80f58ac78675e0d0ca7a70c9f68

SHA-1:
34ff6b8be6a16983cb36ac8f120f67eb6bca05f5

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/26/2024 10:42:46 AM UTC  (today)

File size:
1.7 MB (1,758,528 bytes)

Product version:
2, 0, 29, 0

Copyright:
Copyright (C) 2007 NEC Corporation, NEC Personal Products, Ltd.

Original file name:
poplink.exe

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\121ware\121poplink\poplink.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/20/2009 9:00:00 AM

Valid to:
1/21/2010 8:59:59 AM

Subject:
CN="NEC Personal Products, Ltd.", OU=D00, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="NEC Personal Products, Ltd.", L=Shinagawa-ku, S=Tokyo, C=JP

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
3C35EB6EBC98D50241A2DED2B9439BF0

File PE Metadata
Compilation timestamp:
3/16/2009 4:45:35 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
8.0

CTPH (ssdeep):
24576:7OLSU+SORPbi3Iv+G3q/OE+GzEWCAu8TnkQndirX:6OU+nKNG3mz+Gzn71TnLndU

Entry address:
0x9334D

Entry point:
E8, 34, F2, 00, 00, E9, 16, FE, FF, FF, 55, 8B, EC, 83, EC, 20, 8B, 45, 08, 56, 57, 6A, 08, 59, BE, A4, 09, 4F, 00, 8D, 7D, E0, F3, A5, 89, 45, F8, 8B, 45, 0C, 85, C0, 5F, 89, 45, FC, 5E, 74, 0C, F6, 00, 08, 74, 07, C7, 45, F4, 00, 40, 99, 01, 8D, 45, F4, 50, FF, 75, F0, FF, 75, E4, FF, 75, E0, FF, 15, 08, 52, 4E, 00, C9, C2, 08, 00, B8, A7, 30, 4A, 00, A3, B0, 5B, 57, 00, C7, 05, B4, 5B, 57, 00, A3, 27, 4A, 00, C7, 05, B8, 5B, 57, 00, 61, 27, 4A, 00, C7, 05, BC, 5B, 57, 00, 95, 27, 4A, 00, C7, 05, C0, 5B...
 
[+]

Entropy:
5.8539

Code size:
912 KB (933,888 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
POPLINK

Command:
C:\Program Files\121ware\121poplink\poplink.exe \startuprun


Scan poplink.exe - Powered by Reason Core Security