ww.exe

Weather Watcher Live

Singer's Creations

It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘WeatherWatcherLive’.
Publisher:
Singer's Creations  (signed and verified)

Product:
Weather Watcher Live

Version:
7.01.0094

MD5:
d58e7f5d36d97d08245b6c2e2c36427b

SHA-1:
878d0875e85945ab279a9682b7cbe8676ef2d43a

SHA-256:
9ec6dfe304b1ea02d9ddfcd0b0c80b4f3431afa03080ee688c03fcbcb670cb11

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/25/2024 7:22:37 AM UTC  (today)

File size:
2 MB (2,095,272 bytes)

Product version:
7.01.0094

Copyright:
Copyright © 2013 Mike Singer

Original file name:
ww.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\weather watcher live\ww.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
7/1/2012 7:00:00 PM

Valid to:
7/2/2013 6:59:59 PM

Subject:
CN=Singer's Creations, O=Singer's Creations, STREET=PO Box 126611, L=Harrisburg, S=PA, PostalCode=17112, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
74E1CB95C8CDDF8B339021A86EBD44FD

File PE Metadata
Compilation timestamp:
6/16/2013 7:39:25 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
24576:YayWmI4ovi1xdQ+OoYzZK1PNs5Zu+VQ43Dxw9iXGPGN0tMF9Dh24PEtiVjdDele9:niN1hOoYzs1F9KNDs5wqU

Entry address:
0x1ADF0

Entry point:
68, 24, B6, 41, 00, E8, F0, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 68, 00, 00, 00, 48, 00, 00, 00, 92, 42, DD, 4E, 0F, 01, B2, 46, 88, A6, F4, A3, E8, 48, 59, 1D, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 00, 00, 58, 68, 3D, 00, 57, 65, 61, 74, 68, 65, 72, 57, 61, 74, 63, 68, 65, 72, 4C, 69, 76, 65, 00, 00, 00, 00, 00, 00, 59, 6F, 75, 72, 20, 64, 65, 73, 6B, 74, 6F, 70, 20, 77, 65, 61, 74, 68, 65, 72, 20, 73, 74, 61, 74, 69, 6F, 6E, 00, 00, 00, 80, 00, 00, 00, 00, 01, 00, 2A, 00, 9C, CF, 42, 00...
 
[+]

Entropy:
5.8677

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
2 MB (2,076,672 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
WeatherWatcherLive

Command:
"C:\Program Files\weather watcher live\ww.exe"


Scan ww.exe - Powered by Reason Core Security