iehelper.exe

Western Web Applications, LLC

This adware background process is controlled and started by the Updater.exe executable (if the process is stopped the updater will restart it) and is desigend to install the BHO/toolbar within the Internet Explorer web borwser and inject and popup various types of ad formats including pop-ups, inline text links and banners. IeHelper is packaged with one of many a branded adware applications (websteriods), from Injekt. The application iehelper.exe by Western Web Applications has been detected as adware by 10 anti-malware scanners.
Publisher:
WatchDog  (signed by Western Web Applications, LLC)

Product:
WatchDog

Version:
3, 0, 0, 1

MD5:
36a6148fba1badb89f721c3d1ed234e9

SHA-1:
a55f0617307cfb1e67f963354eb6d2ec3e28f133

SHA-256:
4223b4c8658460982a5f2775e7513c3050687873fe4162429ecbf636ae3ef7fe

Scanner detections:
10 / 68

Status:
Adware

Explanation:
Injects display ads (banner ads), in-text ads, interstitial ads, or other types of ads in the web browser as well as alters the browsers settings (home page, search, DNS, and security protocols).

Analysis date:
4/29/2024 5:49:53 PM UTC  (today)

Scan engine
Detection
Engine version

AVG
Generic
2016.0.3145

Dr.Web
Adware.Plugin.128
9.0.1.05190

ESET NOD32
Win32/ExFriendAlert (variant)
9.10682

herdProtect (fuzzy)
2014.1.28.1

IKARUS anti.virus
PUA.ExFriendAlert
t3scan.1.8.3.0

Malwarebytes
PUP.Optional.SearchDonkey.A
v2014.01.28.01

NANO AntiVirus
Riskware.Win32.Plugin.dbxktm
0.28.2.61721

Reason Heuristics
PUP.WesternWebApplications.I
14.4.7.1

Sophos
Search Donkey
4.98

VIPRE Antivirus
SearchDonkey
23830

File size:
246.6 KB (252,568 bytes)

Product version:
3, 0, 0, 1

Original file name:
dog.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\rhelpers\iehelper\iehelper.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
5/23/2013 7:00:00 PM

Valid to:
5/24/2014 6:59:59 PM

Subject:
CN="Western Web Applications, LLC", O="Western Web Applications, LLC", STREET=640 E Grand Ave, STREET=Suite 129, L=Carlsbad, S=CA, PostalCode=92008, C=US

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
2A1B337726D509D16C17362E2E625DE9

File PE Metadata
Compilation timestamp:
9/24/2013 6:21:18 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
3072:71hDqIZLwlmnWN/68zIyrjSHoWT0Cp2kL93YabMtfxMKZ4b+Wry9n5XtQwnPM2b6:711JZc3sZ1sD46/PQAEjN5DTF6CvX

Entry address:
0x160EB

Entry point:
E8, 68, 96, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 8B, 45, 08, 85, C0, 74, 12, 83, E8, 08, 81, 38, DD, DD, 00, 00, 75, 07, 50, E8, F8, D4, FF, FF, 59, 5D, C3, 8B, FF, 55, 8B, EC, 83, EC, 10, A1, 20, 29, 43, 00, 33, C5, 89, 45, FC, 8B, 55, 18, 53, 33, DB, 56, 57, 3B, D3, 7E, 1F, 8B, 45, 14, 8B, CA, 49, 38, 18, 74, 08, 40, 3B, CB, 75, F6, 83, C9, FF, 8B, C2, 2B, C1, 48, 3B, C2, 7D, 01, 40, 89, 45, 18, 89, 5D, F8, 39, 5D, 24, 75, 0B, 8B, 45, 08, 8B, 00, 8B, 40, 04, 89, 45, 24, 8B, 35, CC, 90, 42, 00...
 
[+]

Entropy:
6.3438

Code size:
159.5 KB (163,328 bytes)

Remove iehelper.exe - Powered by Reason Core Security