registryhelpersetup_cs_installer.exe

Registry Helper

SafeApp Software, LLC

The application registryhelpersetup_cs_installer.exe by SafeApp Software has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.safeappsoftware.com.
Publisher:
SafeApp Software, LLC  (signed and verified)

Product:
Registry Helper

Version:
3.0.260

MD5:
d87c2aa8a685356659e4d0b0ab92659d

SHA-1:
773ddc9bc61fb5203149e494b0c5cab66019b793

SHA-256:
ae126a0ed1c5a5468c1ea302794b224b0c2af9e4cd25f7e4cafeb1c6fcd86d86

Scanner detections:
1 / 68

Status:
Potentially unwanted

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
5/3/2024 2:29:34 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP (M)
16.10.22.7

File size:
7.2 MB (7,498,584 bytes)

Product version:
3.0.260

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\registryhelpersetup_cs_installer.exe

Digital Signature
Authority:
Symantec Corporation

Valid from:
3/3/2016 12:00:00 AM

Valid to:
3/3/2017 11:59:59 PM

Subject:
CN="SafeApp Software, LLC", O="SafeApp Software, LLC", L=Harrison, S=New York, C=US

Issuer:
CN=Symantec Class 3 SHA256 Code Signing CA, OU=Symantec Trust Network, O=Symantec Corporation, C=US

Serial number:
06D471D9E54167BDE3638A5B01AFBBEE

File PE Metadata
Compilation timestamp:
10/7/2014 5:40:20 AM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:JXBVC9qTcinlxpoKlIGN+7YPLZfOyKs4ArW3S/F3uwOrLIS:JRVC4xlLzpQ2Zas4ArW3MF3uwUl

Entry address:
0x335A

Entry point:
81, EC, D8, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 30, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, BC, 70, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 09, A3, B8, 92, 42, 00, E8, 15, 2F, 00, 00, A3, 04, 92, 42, 00, 55, 8D, 44, 24, 38, 68, B4, 02, 00, 00, 50, 55, 68, A8, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, 7C, 93, 40, 00, 68, 00, 82, 42, 00, E8, 80, 2B, 00, 00, FF, 15, 34, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, 6E, 2B, 00, 00...
 
[+]

Entropy:
7.9997

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file registryhelpersetup_cs_installer.exe has been seen being distributed by the following URL.

http://www.safeappsoftware.com/.../RegistryHelperSetup_CS_Installer.exe

Remove registryhelpersetup_cs_installer.exe - Powered by Reason Core Security