iehelper.exe

Data Beat Solutions, LLC

This adware background process is controlled and started by the Updater.exe executable (if the process is stopped the updater will restart it) and is desigend to install the BHO/toolbar within the Internet Explorer web borwser and inject and popup various types of ad formats including pop-ups, inline text links and banners. IeHelper is packaged with one of many a branded adware applications (websteriods), from Injekt. The application iehelper.exe by Data Beat Solutions has been detected as adware by 7 anti-malware scanners.
Publisher:
WatchDog  (signed by Data Beat Solutions, LLC)

Product:
WatchDog

Version:
3, 0, 0, 1

MD5:
e815802a57970ae3a4f6ccf3482a66db

SHA-1:
0a8194ffe5bbca9afdfa71aabfee03ec13dc8779

SHA-256:
f1bd02b2aa0ff150428c5085ff71ad665c88a67801877fb73c5d20ded1acefba

Scanner detections:
7 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/26/2024 9:46:37 PM UTC  (today)

Scan engine
Detection
Engine version

herdProtect (fuzzy)
2014.4.6.15

Malwarebytes
PUP.Optional.SearchDonkey.A
v2014.02.06.12

McAfee
Artemis!592B06E131E1
5600.7168

Reason Heuristics
PUP.DataBeatSolutions.I
14.8.8.0

Sophos
Search Donkey
4.96

Trend Micro House Call
TROJ_GEN.F47V1030
7.2.37

VIPRE Antivirus
SearchDonkey
24390

File size:
245.9 KB (251,784 bytes)

Product version:
3, 0, 0, 1

Original file name:
dog.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\rhelpers\iehelper\iehelper.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
6/3/2013 8:00:00 PM

Valid to:
6/4/2014 7:59:59 PM

Subject:
CN="Data Beat Solutions, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Data Beat Solutions, LLC", L=San Diego, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
5D5E53357F69EB288E21F6DAE0D015A6

File PE Metadata
Compilation timestamp:
10/9/2013 4:45:34 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:clBzqIELQlmnWN/68zIyrjSHoWT0Cp2kL93YabMtfxYCZYzVnr69n+/Vgw3PMYbn:cllk5c3sZ1sHYZ2ogQkGtzsThSC5C

Entry address:
0x160EB

Entry point:
E8, 68, 96, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, F8, D4, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, 20, 29, 43, 00, 33, C5, 89, 45, FC, 8B, 55, 18, 53, 33, DB, 56, 57, 3B, D3, 7E, 1F, 8B, 45, 14, 8B, CA, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, C2, 2B, C1, 48, 3B, C2, 7D, 01, 40, 89, 45, 18, 89, 5D, F8, 39, 5D, 24, 75, 0B, 8B, 45, 08, 8B, 00, 8B, 40, 04, 89, 45, 24, 8B, 35, CC, 90, 42, 00...
 
[+]

Entropy:
6.3367

Code size:
159.5 KB (163,328 bytes)

Remove iehelper.exe - Powered by Reason Core Security