chromehelper.exe

Injekt LLC

This adware background process is controlled and started by the Updater.exe executable (if the process is stopped the updater will restart it) and is desigend to install the extension within the Chrome borwser and inject and popup various types of ad formats including pop-ups, inline text links and banners. ChromeHelper is packaged with one of many a branded adware applications, from Injekt. The application chromehelper.exe by Injekt has been detected as adware by 4 anti-malware scanners.
Publisher:
WatchDog  (signed by Injekt LLC)

Product:
WatchDog

Version:
3, 0, 0, 1

MD5:
542c021b0f649c33c5d346c61f86fbdf

SHA-1:
5ed1e41c49c51e5ea061ca5fbac0ee32fa48ec08

SHA-256:
a8809a8a4de7db082a759c3341f2e041668d0c0577f20198f240ccb47dcc5e5a

Scanner detections:
4 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/19/2024 2:46:47 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Win32/DH
2015.0.3494

Kaspersky
HEUR:Trojan-Downloader.Win32.Generic
14.0.0.3967

Malwarebytes
PUP.Optional.MultiExtension.A
v2014.04.24.12

Reason Heuristics
PUP.Injekt.M
14.8.8.3

File size:
424.3 KB (434,528 bytes)

Product version:
3, 0, 0, 1

Original file name:
dog.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\rhelpers\chromehelper\chromehelper.exe

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
3/22/2014 8:00:00 PM

Valid to:
6/22/2015 7:59:59 PM

Subject:
CN=Injekt LLC, OU=Digital ID Class 3 - Microsoft Software Validation v2, O=Injekt LLC, L=Carlsbad, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
22388FB3C3238D36E8B8ABBBE3903F04

File PE Metadata
Compilation timestamp:
4/17/2014 8:22:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
6144:uomFZNQvOUNDAqpq2UVVnuynFn+WcbgHCFXMiuhjJy:uVFZNAOUNDAp2UVnu6HcbXIhly

Entry address:
0x30F42

Entry point:
E8, F8, DE, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, 3C, F5, 70, C9, 45, 00, 00, 75, 13, 56, E8, 71, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 11, E8, D4, 5A, 00, 00, 59, FF, 34, F5, 70, C9, 45, 00, FF, 15, 74, C0, 44, 00, 5E, 5D, C3, 56, 57, BE, 70, C9, 45, 00, 8B, FE, 53, 8B, 1F, 85, DB, 74, 17, 83, 7F, 04, 01, 74, 11, 53, FF, 15, 7C, C0, 44, 00, 53, E8, 83, BB, FF, FF, 83, 27, 00, 59, 83, C7, 08, 81, FF, 90, CA, 45, 00, 7C, D8, 5B, 83, 3E, 00, 74, 0E, 83, 7E, 04, 01, 75, 08, FF, 36, FF, 15...
 
[+]

Entropy:
6.4012

Code size:
299.5 KB (306,688 bytes)

Remove chromehelper.exe - Powered by Reason Core Security