RegistryHelper.exe

Registry Helper

SafeApp Software, LLC

The application RegistryHelper.exe by SafeApp Software has been detected as a potentially unwanted program by 2 anti-malware scanners.
Publisher:
SafeApp Software, LLC  (signed and verified)

Product:
Registry Helper

Version:
2.00.0588

MD5:
73a4018c7ad96c7da898086eb064851c

SHA-1:
12a692c31e90d3b36d6f3f99aaa6b52016a5cd72

SHA-256:
b718887bedfeb1628b8efb0098d93554ce98408eca1f2fff836e6c50df933de3

Scanner detections:
2 / 68

Status:
Potentially unwanted

Analysis date:
4/26/2024 9:10:16 PM UTC  (today)

Scan engine
Detection
Engine version

G Data
Win32.Application.RegistryHelper
15.7.24

Reason Heuristics
PUP.SafeAppSoftware (M)
15.7.30.11

File size:
4.6 MB (4,826,408 bytes)

Product version:
2.00.0588

Copyright:
Copyright 2006-2009, SafeApp Software, LLC.

Trademarks:
Registry Helper is a registered trademark of SafeApp Software, LLC

Original file name:
RegistryHelper.exe

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\Program Files\registry helper\registryhelper.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
5/13/2008 2:00:00 AM

Valid to:
7/12/2009 1:59:59 AM

Subject:
CN="SafeApp Software, LLC", OU=Digital ID Class 3 - Microsoft Software Validation v2, O="SafeApp Software, LLC", L=Harrison, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2004 CA, OU=Terms of use at https://www.verisign.com/rpa (c)04, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
20B2054225E5E90BE70636CB454EA531

File PE Metadata
Compilation timestamp:
3/25/2009 8:13:53 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
98304:Vddw2V2IdxQQaC/7tjYzwWvkLrtGEjqEhHZq57p6q99Nyw0ha6jyZdXVTDJD8te+:LQIdx1hTtjYzwWvkLrtGEjqEhHZq57pq

Entry address:
0x18D5C

Entry point:
68, D0, 97, 41, 00, E8, EE, FF, FF, FF, 00, 00, 00, 00, 00, 00, 30, 00, 00, 00, 50, 00, 00, 00, 40, 00, 00, 00, 75, FE, E8, 46, 24, BE, E0, 4A, B1, F3, 46, AF, EA, DB, 59, 1B, 00, 00, 00, 00, 00, 00, 01, 00, 00, 00, 41, 00, 06, 50, 83, 02, 52, 65, 67, 69, 73, 74, 72, 79, 48, 65, 6C, 70, 65, 72, 00, 00, 52, 65, 67, 69, 73, 74, 72, 79, 20, 48, 65, 6C, 70, 65, 72, 00, 00, 00, 00, 00, FF, CC, 31, 00, 06, CD, EA, DF, FE, C1, 82, EC, 4D, BC, 6B, B4, B4, D3, 5C, C5, 46, 3B, 3E, 56, 0C, 6F, 16, 36, 43, B5, 5A, 8E...
 
[+]

Developed / compiled with:
Microsoft Visual Basic v5.0/v6.0

Code size:
4.4 MB (4,632,576 bytes)

Remove RegistryHelper.exe - Powered by Reason Core Security