registryhelpersetup_cb_installer.exe

Registry Helper

SafeApp Software, LLC

The application registryhelpersetup_cb_installer.exe by SafeApp Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.safeappsoftware.com.
Publisher:
SafeApp Software, LLC  (signed and verified)

Product:
Registry Helper

Version:
3.0.260

MD5:
31794b33b529d383aedfc335069239b1

SHA-1:
c02fe32f5dd6ab6759a54b1310a970bcda614cf2

SHA-256:
1d8c1ba5034e92e26befcf77e62dcd2a1f0ad7ff7f3065f3cf95d359606d2104

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/3/2024 2:32:08 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.SafeAppS.Installer (M)
16.4.23.14

File size:
7.2 MB (7,497,368 bytes)

Product version:
3.0.260

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\registryhelpersetup_cb_installer.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
3/3/2016 1:00:00 AM

Valid to:
3/4/2017 12:59:59 AM

Subject:
CN="SafeApp Software, LLC", O="SafeApp Software, LLC", L=Harrison, S=New York, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
06D471D9E54167BDE3638A5B01AFBBEE

File PE Metadata
Compilation timestamp:
10/7/2014 6:40:20 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:eqYIne+YMjNvOS74SpzncNuMIkwaYcejHGIW:etqe+1jNvOSskcNuMnvYceW

Entry address:
0x335A

Entry point:
81, EC, D8, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 30, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, BC, 70, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 09, A3, B8, 92, 42, 00, E8, 15, 2F, 00, 00, A3, 04, 92, 42, 00, 55, 8D, 44, 24, 38, 68, B4, 02, 00, 00, 50, 55, 68, A8, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, 7C, 93, 40, 00, 68, 00, 82, 42, 00, E8, 80, 2B, 00, 00, FF, 15, 34, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, 6E, 2B, 00, 00...
 
[+]

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file registryhelpersetup_cb_installer.exe has been seen being distributed by the following URL.

http://www.safeappsoftware.com/.../RegistryHelperSetup_CB_Installer.exe

Remove registryhelpersetup_cb_installer.exe - Powered by Reason Core Security