rchelper.exe

Registry Repair Wizard

CleanMyPC Technology Limited

The application rchelper.exe, “Registry Repair Wizard Scheduler” by CleanMyPC Technology Limited has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It is set to automatically start when a user logs into Windows via the current user run registry key under the display name ‘Registry Repair Wizard Scheduler’. This file is typically installed with the program Registry Repair Wizard by SmartPCTools.
Publisher:
SmartPCTools  (signed by CleanMyPC Technology Limited)

Product:
Registry Repair Wizard

Description:
Registry Repair Wizard Scheduler

Version:
2012, 6, 7, 2

MD5:
082c74737b56c130793a3415631cfe8f

SHA-1:
578af77dc032267cb4d95845c813caabfe8f6714

SHA-256:
fd9c1631240bd6f3849820bca4509ee68c6d10ea39863c7dd662315969b859a6

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
4/20/2024 6:56:40 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Optional.Startup
15.4.1.17

File size:
1.5 MB (1,542,936 bytes)

Product version:
2012, 6, 7, 2

Copyright:
Copyright (C) 2004-2012

Original file name:
RCScheduler.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\smartpctools\registry repair wizard\rchelper.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/28/2012 8:00:00 PM

Valid to:
3/29/2017 7:59:59 PM

Subject:
CN=CleanMyPC Technology Limited, O=CleanMyPC Technology Limited, STREET="ROOM C1D 6/F, WING HING INDUSTRIAL BUILDING", STREET=14 HING YIP STREET, STREET="KWUN TONG, KOWLOON", L=HONG KONG, S=NA, PostalCode=NA, C=HK

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B22D5ED33A336918E76BE3A5C6CB25F1

File PE Metadata
Compilation timestamp:
6/10/2012 6:01:14 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
83.82

CTPH (ssdeep):
24576:gS8Y21FqZlcHPCzoR2KvqTry0IVyBGaNI1EnKw7Zq0uX+l79IHyVwyShviRS3Pgw:RaFqTG5y3m1EnKw7Zq0uX+l79IHyVwye

Entry address:
0xB0000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB, 0F, B8, EB, 07, B9, EB, 0F, 90, EB, 08, FD, EB, 0B, F2, EB, F5, EB, F6, F2, EB, 08, FD, EB, E9, F3, EB, E4, FC, E9, 9D, 0F, C9, 8B, CA, F7, D1, 59, 58, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB, 0F, B8, EB, 07, B9, EB, 0F, 90, EB, 08, FD, EB, 0B, F2, EB, F5, EB, F6, F2, EB, 08, FD, EB, E9, F3, EB, E4, FC, E9, 9D, 0F, C9, 8B, CA, F7, D1, 59, 58, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB...
 
[+]

Entropy:
7.7813

Packer / compiler:
ASPack v1.08.04

Code size:
444 KB (454,656 bytes)

Startup File (User Run)
Registry location:
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Registry Repair Wizard Scheduler

Command:
"C:\Program Files\smartpctools\registry repair wizard\rchelper.exe" \startup


The file rchelper.exe has been discovered within the following program.

Registry Repair Wizard  by SmartPCTools
SmartPCTools Registry Repair Wizard is registry utility whose purported purpose is to remove redundant items from the Windows registry.
www.registryrepair.net
51% remove it
 
Powered by Should I Remove It?

Remove rchelper.exe - Powered by Reason Core Security