wshelper.exe

Wondershare Studio

Wondershare software CO., LIMITED

It is set to automatically execute when any user logs into Windows (through the local user run registry setting) with the name ‘Wondershare Helper Compact.exe’.
Publisher:
Wondershare  (signed by Wondershare software CO., LIMITED)

Product:
Wondershare Studio

Version:
2.3.0.1

MD5:
641ce4054ddce224e0ba4881807599ac

SHA-1:
fbca20d2d00c2ca4bedea44c892136b66c7fa156

SHA-256:
2734aeec3cea30519c3949f55cddc6decc0933d1c8343ed038cd3e5e6320a226

Scanner detections:
38 / 68

Status:
Clean  (38 probable false positive detections)

Explanation:
These detections are probably false positives (erroneous), the file is probably malware free.

Analysis date:
4/27/2024 12:13:46 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Win32.Neshta.C
362

Agnitum Outpost
Win32.Neshta.A
7.1.1

AhnLab V3 Security
Win32/Neshta
2013.08.22

Avira AntiVirus
W32/Delf.I
7.11.30.172

avast!
Win32:Apanas [Trj]
2014.9-160208

AVG
Win32/Selges.D
2017.0.2840

Baidu Antivirus
Virus.Win32.Neshta.$a
4.0.3.1628

Bitdefender
Win32.Neshta.A
1.0.20.195

Bkav FE
W32.HanGu.PE
1.3.0.4959

Clam AntiVirus
Neshta.B
0.98/19042

Comodo Security
Win32.Neshta.A
16801

Dr.Web
Win32.HLLP.Neshta
9.0.1.039

Emsisoft Anti-Malware
Win32.Neshta
8.16.02.08.12

ESET NOD32
Win32/Neshta.B virus
10.7.0.302.0

Fortinet FortiGate
W32/Neshta.A
2/8/2016

F-Prot
W32/HLLP.41472
v6.4.6.5.141

F-Secure
Win32.Neshta.A
11.2016-08-02_2

G Data
Win32.Neshta
16.2.22

IKARUS anti.virus
Virus.Win32.Neshta
t3scan.2.0.127

Kaspersky
Virus.Win32.Neshta
14.0.0.695

Malwarebytes
Trojan.Agent
v2016.02.08.12

McAfee
W32/HLLP.41472.e
5600.6496

Microsoft Security Essentials
1.163.1557.0

MicroWorld eScan
Win32.Neshta.A
17.0.0.117

NANO AntiVirus
Virus.Win32.Neshta.cdby
0.26.0.53954

Norman
Neshta.C
11.20160208

nProtect
Virus/W32.Neshta
13.08.21.03

Panda Antivirus
W32/Neshta.A
16.02.08.12

Qihoo 360 Security
Virus.Win32.Neshta.B
1.0.0.1015

Quick Heal
W32.Neshta.A
2.16.12.00

Rising Antivirus
Win32.Netsha.a
23.00.65.16206

Sophos
W32/Bloat-A
4.91

Total Defense
Win32/Neshta.A
37.0.10498

Trend Micro House Call
PE_NESHTA.A
7.2.39

Trend Micro
PE_NESHTA.A
10.465.08

Vba32 AntiVirus
Virus.Win32.Neshta.a
3.12.22.3

VIPRE Antivirus
Virus.Win32.Neshta.a
20730

ViRobot
Win32.Neshta.B
2011.4.7.4223

File size:
2 MB (2,087,264 bytes)

Product version:
2.3.0.1

Copyright:
Copyright (c) 2014 Wondershare. All rights reserved

Trademarks:
Wondershare

Original file name:
Wondershare Studio

File type:
Executable application (Win32 EXE)

Language:
Chinese

Common path:
C:\Program Files\common files\wondershare\wondershare helper compact\wshelper.exe

Digital Signature
Authority:
VeriSign, Inc.

Valid from:
2/20/2014 7:00:00 PM

Valid to:
2/21/2016 6:59:59 PM

Subject:
CN="Wondershare software CO., LIMITED", OU=R & D Management, OU=Digital ID Class 3 - Microsoft Software Validation v2, O="Wondershare software CO., LIMITED", L=Shenzhen, S=Guangdong, C=CN

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
30DC6C3A7D282A8E5552CEB78E4C075A

File PE Metadata
Compilation timestamp:
9/11/2014 5:10:09 AM

OS version:
5.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
2.25

CTPH (ssdeep):
24576:uH2W0CUY+d0EPGYY0/P/fqrFpSZVmYHrYBUkkFARWmATRqUXrnTa8OGPbQX6ujM8:Ip5DPDar/cxj8U1t4rDOgkTtTl859343

Entry address:
0x1AA428

Entry point:
55, 8B, EC, 83, C4, E0, 33, C0, 89, 45, E0, 89, 45, E4, 89, 45, EC, 89, 45, E8, B8, 20, 7F, 5A, 00, E8, 92, F2, E5, FF, 33, C0, 55, 68, E3, A5, 5A, 00, 64, FF, 30, 64, 89, 20, E8, F7, D9, FF, FF, A1, B0, A8, 5B, 00, 8B, 00, E8, 1F, 47, E6, FF, 84, C0, 0F, 84, 48, 01, 00, 00, 8D, 55, E8, 33, C0, E8, F5, 90, E5, FF, 8B, 45, E8, 8D, 55, EC, E8, 16, 4D, E6, FF, 8D, 45, EC, BA, FC, A5, 5A, 00, E8, BD, C7, E5, FF, 8B, 4D, EC, B2, 01, A1, 48, 71, 4C, 00, E8, 26, 0C, F2, FF, 8B, 15, 2C, A2, 5B, 00, 89, 02, E8, CD...
 
[+]

Developed / compiled with:
Microsoft Visual C++

Code size:
1.7 MB (1,740,800 bytes)

Startup File (All Users Run)
Registry location:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Name:
Wondershare Helper Compact.exe

Command:
C:\Program Files\common files\wondershare\wondershare helper compact\wshelper.exe


Scan wshelper.exe - Powered by Reason Core Security