actionhelper.dll

Reincubate Ltd

This is installed with iPhone Backup Extractor.
Publisher:
Reincubate Ltd  (signed and verified)

MD5:
3666dcb547e483ee9d142cf286a038e5

SHA-1:
d793ed616bf463c8901e913fa397b02de93009f4

SHA-256:
7b2dd552c87849d614514df2b45974347ed55aa8a7aa25f76e9129e97e2373da

Scanner detections:
0 / 68

Status:
Clean (as of last analysis)

Analysis date:
4/24/2024 10:58:22 PM UTC  (today)

File size:
23.9 MB (25,092,216 bytes)

File type:
Dynamic link library (Win32 DLL)

Common path:
C:\users\{user}\appdata\roaming\reincubate\iphone backup extractor\actionhelper.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
4/23/2014 8:00:00 PM

Valid to:
6/22/2016 7:59:59 PM

Subject:
CN=Reincubate Ltd, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Reincubate Ltd, L=London, S=London, C=GB

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
626DBE65C8A3CD1B464DB33676FDCCA1

File PE Metadata
Compilation timestamp:
12/21/2015 1:36:24 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
12.0

CTPH (ssdeep):
393216:eBTLtI9o8iMg/EjhFUCNEkAkAursk3PxuHFO71lpoIRzRZFkL1+HnXM9bsmgzlXc:epRT63xAk/rskZaA71lpoYzzFkL8vmgm

Entry address:
0x185F335

Entry point:
57, E8, 62, D1, F0, FF, 17, 66, 19, 42, AD, 72, 1B, B9, A5, 0E, B1, E3, 1B, 5C, 4D, 17, 9E, 2F, D6, 0E, D6, F8, 17, A0, BF, 8B, 9C, 25, CD, 55, 17, EE, 06, D3, 0C, 2D, A0, CC, 7C, 09, 4B, 3C, C4, 3B, 68, 00, 11, 20, 19, F2, A9, 2E, 3F, 81, A0, 1E, 2F, 85, CA, 39, C6, 59, 96, 49, 97, 98, 61, E0, 79, 90, 66, 3D, 44, 75, E6, 5B, 7B, EE, 7A, 0B, D0, 14, 90, FA, C0, E0, 7C, A1, 4C, BD, C2, 91, 9E, ED, 3B, 53, BB, 21, F7, 0D, 12, 16, 47, BF, 91, EB, 1D, 54, F4, 83, CA, 49, 2E, 54, 2A, 37, 06, 70, 7C, 45, D5, B4...
 
[+]

Entropy:
7.8328  (probably packed)

Code size:
1.8 MB (1,847,296 bytes)

The file actionhelper.dll has been discovered within the following program.

iPhone Backup Extractor  by Reincubate Ltd
About 4% of users remove it
 
Powered by Should I Remove It?

Scan actionhelper.dll - Powered by Reason Core Security