ext_helper.exe

Dynamo Toolbar Helper

search core systems

The application ext_helper.exe, “Installs and Manages the Dynamo Toolbar” by search core systems has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
search core systems  (signed and verified)

Product:
Dynamo Toolbar Helper

Description:
Installs and Manages the Dynamo Toolbar

Version:
1.0.0.1

MD5:
e06e3d1f80322a6301dffb66e63d93f3

SHA-1:
d00470116b2b127a73f52446a2b1322626f28e38

SHA-256:
e0a5e8c0c8c26e951d0451bf7a3d0a6a822b4d4d2cd876099798dbf56a9199ec

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
4/18/2024 11:09:31 PM UTC  (a few moments ago)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.searchcoresystems.Toolbar (M)
15.12.18.9

File size:
288.5 KB (295,416 bytes)

Product version:
1.3.0.0

Copyright:
Copyright (C) 2013

Original file name:
toolbar_helper.exe

File type:
Executable application (Win32 EXE)

Language:
English

Common path:
C:\Program Files\search core systems\browser components addon\ext_helper.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
1/4/2013 3:59:54 PM

Valid to:
2/13/2014 1:23:54 PM

Subject:
CN=search core systems, O=search core systems, C=CA

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
112124FE4C6C2D17B0B15C854404D8901A2F

File PE Metadata
Compilation timestamp:
6/5/2013 2:05:08 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
6144:fjplQ4u3jwgtiAZnv+DffJpdTN/3xosKhuIQn:fjpa4u0gYsWDffJpdT/oss6n

Entry address:
0x22336

Entry point:
E8, 66, 78, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 33, C9, 3B, 04, CD, 38, 22, 44, 00, 74, 13, 41, 83, F9, 2D, 72, F1, 8D, 48, ED, 83, F9, 11, 77, 0E, 6A, 0D, 58, 5D, C3, 8B, 04, CD, 3C, 22, 44, 00, 5D, C3, 05, 44, FF, FF, FF, 6A, 0E, 59, 3B, C8, 1B, C0, 23, C1, 83, C0, 08, 5D, C3, E8, 72, 3D, 00, 00, 85, C0, 75, 06, B8, A0, 23, 44, 00, C3, 83, C0, 08, C3, E8, 5F, 3D, 00, 00, 85, C0, 75, 06, B8, A4, 23, 44, 00, C3, 83, C0, 0C, C3, 8B, FF, 55, 8B, EC, 56, E8, E2, FF, FF, FF, 8B, 4D, 08...
 
[+]

Entropy:
6.5232

Code size:
217.5 KB (222,720 bytes)

Remove ext_helper.exe - Powered by Reason Core Security