rchelper.exe

Registry Repair Wizard

CleanMyPC Technology Limited

The application rchelper.exe, “Registry Repair Wizard Scheduler” by CleanMyPC Technology Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. This file is typically installed with the program Registry Repair Wizard by SmartPCTools.
Publisher:
SmartPCTools  (signed by CleanMyPC Technology Limited)

Product:
Registry Repair Wizard

Description:
Registry Repair Wizard Scheduler

Version:
2011, 6, 4, 1

MD5:
05244bb9daa0f65fe90166ae2b6aa3a7

SHA-1:
12e8427583d8bc039deb19cc4e480df4ced7ab16

SHA-256:
dc3e80e55be5947fb32f9706e344848c3109f8ca2392051769ca94ff02ca7050

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 3:26:07 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Win32.Generic.CleanMyPCTechnology.Meta
15.11.21.1

File size:
1.5 MB (1,540,480 bytes)

Product version:
2011, 6, 4, 1

Copyright:
Copyright (C) 2004-2011

Original file name:
RCScheduler.EXE

File type:
Executable application (Win32 EXE)

Common path:
C:\Program Files\smartpctools\registry repair wizard\rchelper.exe

Digital Signature
Authority:
The USERTRUST Network

Valid from:
3/22/2010 3:00:00 AM

Valid to:
3/22/2012 2:59:59 AM

Subject:
CN=CleanMyPC Technology Limited, O=CleanMyPC Technology Limited, STREET="ROOM C1D 6/F, WING HING INDUSTRIAL BUILDING", STREET=14 HING YIP STREET, STREET="KWUN TONG, KOWLOON, HONG KONG", L=HONG KONG, S=NA, PostalCode=NA, C=HK

Issuer:
CN=UTN-USERFirst-Object, OU=http://www.usertrust.com, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

Serial number:
253A6CD8243978CADEED6FF2D0C2F4E1

File PE Metadata
Compilation timestamp:
12/23/2010 6:34:35 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
83.82

CTPH (ssdeep):
24576:QS8Y21FqZlcHPCzoR2KSqTrsOzTZoQjZYQA1EnKw7Zq0uX+l79IHyVwyShviRS3k:hacqToWZbZA1EnKw7Zq0uX+l79IHyVws

Entry address:
0xB0000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB, 0F, B8, EB, 07, B9, EB, 0F, 90, EB, 08, FD, EB, 0B, F2, EB, F5, EB, F6, F2, EB, 08, FD, EB, E9, F3, EB, E4, FC, E9, 9D, 0F, C9, 8B, CA, F7, D1, 59, 58, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB, 0F, B8, EB, 07, B9, EB, 0F, 90, EB, 08, FD, EB, 0B, F2, EB, F5, EB, F6, F2, EB, 08, FD, EB, E9, F3, EB, E4, FC, E9, 9D, 0F, C9, 8B, CA, F7, D1, 59, 58, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB...
 
[+]

Entropy:
7.7251

Packer / compiler:
ASPack v1.08.04

Code size:
444 KB (454,656 bytes)

The file rchelper.exe has been discovered within the following program.

Registry Repair Wizard  by SmartPCTools
SmartPCTools Registry Repair Wizard is registry utility whose purported purpose is to remove redundant items from the Windows registry.
www.registryrepair.net
51% remove it
 
Powered by Should I Remove It?

Remove rchelper.exe - Powered by Reason Core Security