firefoxhelper.exe

Creative Island Media, LLC

This adware background process is controlled and started by the Updater.exe executable (if the process is stopped the updater will restart it) and is desigend to install the addon within the Firefox wbe borwser and inject and popup various types of ad formats including pop-ups, inline text links and banners. FirefoxHelper is packaged with one of many a branded adware applications from Injekt. The application firefoxhelper.exe by Creative Island Media has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
WatchDog  (signed by Creative Island Media, LLC)

Product:
WatchDog

Version:
3, 0, 0, 1

MD5:
1ee82743b701ab60c1702f6e19f703c7

SHA-1:
5bd66fed85c245beaceaab63f6a6f53776d8628d

SHA-256:
f646bc51d9a16c137640f0cefc832bd193f6c98bc0a7f3b6843792e141b4e7e5

Scanner detections:
1 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/16/2024 4:26:22 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Injekt (M)
16.12.30.22

File size:
419.9 KB (429,944 bytes)

Product version:
3, 0, 0, 1

Original file name:
dog.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\rhelpers\firefoxhelper\firefoxhelper.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/20/2013 5:00:00 PM

Valid to:
5/21/2014 4:59:59 PM

Subject:
CN="Creative Island Media, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Creative Island Media, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
68F23F4D2767F6491DEA9186F2E5CB89

File PE Metadata
Compilation timestamp:
12/18/2013 1:55:00 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

Entry address:
0x30662

Entry point:
E8, 88, DF, 00, 00, E9, 7F, FE, FF, FF, 55, 8B, EC, 56, 8B, 75, 08, 83, 3C, F5, 70, C9, 45, 00, 00, 75, 13, 56, E8, 71, 00, 00, 00, 59, 85, C0, 75, 08, 6A, 11, E8, 74, 5B, 00, 00, 59, FF, 34, F5, 70, C9, 45, 00, FF, 15, 78, C0, 44, 00, 5E, 5D, C3, 56, 57, BE, 70, C9, 45, 00, 8B, FE, 53, 8B, 1F, 85, DB, 74, 17, 83, 7F, 04, 01, 74, 11, 53, FF, 15, 80, C0, 44, 00, 53, E8, 01, BC, FF, FF, 83, 27, 00, 59, 83, C7, 08, 81, FF, 90, CA, 45, 00, 7C, D8, 5B, 83, 3E, 00, 74, 0E, 83, 7E, 04, 01, 75, 08, FF, 36, FF, 15...
 
[+]

Entropy:
6.4159

Code size:
297 KB (304,128 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to update.betterxperience.com  (54.218.62.24:80)

TCP (HTTP):
Connects to d.pullupdate.com  (54.230.15.37:80)

Remove firefoxhelper.exe - Powered by Reason Core Security