rchelper.exe

Registry Repair Wizard

CleanMyPC Technology Limited

The application rchelper.exe, “Registry Repair Wizard Scheduler” by CleanMyPC Technology Limited has been detected as a potentially unwanted program by 2 anti-malware scanners. This file is typically installed with the program Registry Repair Wizard by SmartPCTools.
Publisher:
SmartPCTools  (signed by CleanMyPC Technology Limited)

Product:
Registry Repair Wizard

Description:
Registry Repair Wizard Scheduler

Version:
2012, 7, 1, 0

MD5:
7a5d31c252fc0422c6aff0422d03f164

SHA-1:
92d2903e9af13f229e8c8c51254e9ffcb6dfa141

SHA-256:
6e5fea0b50351abd43c12c70dcd97829319c2418e705a4e7f22fe602935f9f60

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/19/2024 8:51:27 PM UTC  (today)

Scan engine
Detection
Engine version

Clam AntiVirus
PUA.Packed.Armadillo
0.98/18155

Reason Heuristics
PUP.Optional.CleanMyPCTechnology
15.2.17.9

File size:
1.5 MB (1,542,896 bytes)

Product version:
2012, 7, 1, 0

Copyright:
Copyright (C) 2004-2012

Original file name:
RCScheduler.EXE

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\smartpctools\registry repair wizard\rchelper.exe

Digital Signature
Authority:
COMODO CA Limited

Valid from:
3/28/2012 7:00:00 PM

Valid to:
3/29/2017 6:59:59 PM

Subject:
CN=CleanMyPC Technology Limited, O=CleanMyPC Technology Limited, STREET="ROOM C1D 6/F, WING HING INDUSTRIAL BUILDING", STREET=14 HING YIP STREET, STREET="KWUN TONG, KOWLOON", L=HONG KONG, S=NA, PostalCode=NA, C=HK

Issuer:
CN=COMODO Code Signing CA 2, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

Serial number:
00B22D5ED33A336918E76BE3A5C6CB25F1

File PE Metadata
Compilation timestamp:
5/5/2012 4:26:13 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
83.82

CTPH (ssdeep):
24576:XS8Y21FqZlcHPCzoR2KvqTrkPb3tzQU0IUEUEld1EnKw7Zq0uX+l79IHyVwyShvQ:2a1qTILtp0IJp1EnKw7Zq0uX+l79IHy3

Entry address:
0xB0000

Entry point:
60, E8, 00, 00, 00, 00, 5D, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB, 0F, B8, EB, 07, B9, EB, 0F, 90, EB, 08, FD, EB, 0B, F2, EB, F5, EB, F6, F2, EB, 08, FD, EB, E9, F3, EB, E4, FC, E9, 9D, 0F, C9, 8B, CA, F7, D1, 59, 58, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB, 0F, B8, EB, 07, B9, EB, 0F, 90, EB, 08, FD, EB, 0B, F2, EB, F5, EB, F6, F2, EB, 08, FD, EB, E9, F3, EB, E4, FC, E9, 9D, 0F, C9, 8B, CA, F7, D1, 59, 58, 50, 51, 0F, CA, F7, D2, 9C, F7, D2, 0F, CA, EB, 0F, B9, EB...
 
[+]

Entropy:
7.7271

Packer / compiler:
ASPack v1.08.04

Code size:
444 KB (454,656 bytes)

The file rchelper.exe has been discovered within the following program.

Registry Repair Wizard  by SmartPCTools
SmartPCTools Registry Repair Wizard is registry utility whose purported purpose is to remove redundant items from the Windows registry.
www.registryrepair.net
51% remove it
 
Powered by Should I Remove It?

Remove rchelper.exe - Powered by Reason Core Security