registryhelpersetupam.exe

SafeApp Software, LLC

The application registryhelpersetupam.exe by SafeApp Software has been detected as a potentially unwanted program by 3 anti-malware scanners. The program is a setup application that uses the NSIS (Nullsoft Scriptable Install System) installer. It is also typically executed from the user's temporary directory. The file has been seen being downloaded from www.reghelper.com.
Publisher:
SafeApp Software, LLC  (signed and verified)

MD5:
1da26400da9086eca149e89899244e66

SHA-1:
389074fd02ab04f5eac53bf18ef67047aedabff6

SHA-256:
191bb404d380c34fad4615012bb8f4119bfefede8fcde47eacadd6aba7100148

Scanner detections:
3 / 68

Status:
Potentially unwanted

Analysis date:
6/15/2024 9:45:02 AM UTC  (today)

Scan engine
Detection
Engine version

G Data
Win32.Application.RegistryHelper
15.5.25

Panda Antivirus
PUP/ScamOptimizer
15.05.18.03

Reason Heuristics
PUP.Installer.SafeAppSoftware
15.5.14.6

File size:
6.7 MB (7,029,064 bytes)

File type:
Executable application (Win32 EXE)

Installer:
NSIS (Nullsoft Scriptable Install System)

Common path:
C:\users\{user}\appdata\local\temp\registryhelpersetupam.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
1/6/2015 4:00:00 PM

Valid to:
1/7/2016 3:59:59 PM

Subject:
CN="SafeApp Software, LLC", O="SafeApp Software, LLC", L=Harrison, S=New York, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
057EF95AEE96D23091760F07BE8E21F1

File PE Metadata
Compilation timestamp:
10/6/2014 9:40:20 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
196608:oOvkigzmMniX3BrMRavTupB+SN79fI444+Cevdo4:oOvkigiMnin9MRaul79fIhHd

Entry address:
0x335A

Entry point:
81, EC, D8, 02, 00, 00, 53, 55, 56, 57, 6A, 20, 33, ED, 5E, 89, 6C, 24, 18, C7, 44, 24, 10, 30, 92, 40, 00, 89, 6C, 24, 14, FF, 15, 34, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, BC, 70, 40, 00, 55, FF, 15, AC, 72, 40, 00, 6A, 09, A3, B8, 92, 42, 00, E8, 15, 2F, 00, 00, A3, 04, 92, 42, 00, 55, 8D, 44, 24, 38, 68, B4, 02, 00, 00, 50, 55, 68, A8, 06, 42, 00, FF, 15, 7C, 71, 40, 00, 68, 7C, 93, 40, 00, 68, 00, 82, 42, 00, E8, 80, 2B, 00, 00, FF, 15, 34, 71, 40, 00, BB, 00, 40, 43, 00, 50, 53, E8, 6E, 2B, 00, 00...
 
[+]

Entropy:
7.9997

Packer / compiler:
Nullsoft install system v2.x

Code size:
24 KB (24,576 bytes)

The file registryhelpersetupam.exe has been seen being distributed by the following URL.

Remove registryhelpersetupam.exe - Powered by Reason Core Security