chrlike.exe

Sice Xing

The application chrlike.exe by Sice Xing has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Install Service(ToolrainDL)”.
Publisher:
Sice Xing  (signed and verified)

MD5:
7b4537bffb6c07d640fe769c3df9d906

SHA-1:
cf93096b2e9a9cd457d26ac5bad7cc50a6d639c6

SHA-256:
77312721b295cc758585ba2dcb0685e6ce55a2fa7374318d0215644700fed2a0

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/16/2024 2:44:16 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Elex (M)
16.6.29.10

File size:
477.4 KB (488,832 bytes)

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\tools\chrlike.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
6/27/2016 5:30:00 AM

Valid to:
4/2/2017 5:29:59 AM

Subject:
CN=Sice Xing, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
1ED032BEEC009922FC8C2EE527491299

File PE Metadata
Compilation timestamp:
6/28/2016 6:53:25 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
6144:qLIFKxNeKVxbXOUaQUlS+6IuYIRB8ZcPx6VHUjpUIf/4oTCjqnln2nB:qLcw5eULUl8YW8j01UU5THsnB

Entry address:
0x37DE8

Entry point:
8E, 1A, 72, 00, 00, BD, D1, A7, 99, AB, 85, 57, F8, C7, 14, 00, ED, 19, 8E, 16, D5, 59, 00, 00, 00, 00, 23, 2D, 03, 0A, 0A, D2, 83, 09, 2B, 80, 9F, DF, 1C, A9, 55, 99, 88, 9A, 01, AC, AE, A6, 94, BD, A0, 8D, A3, AB, DA, 14, 8A, 67, B7, 80, B4, 18, A9, A6, 99, A6, 93, BB, A3, AB, AE, 09, 02, AB, 4F, 00, 00, 00, 00, D4, 22, 70, 76, 59, 38, 70, 5D, 0A, 30, 03, F3, 5A, D7, BC, F0, E5, 77, 13, 00, 41, 99, 04, AE, 2C, 9A, 93, 3F, 8E, A3, AB, AE, A6, EB, 11, 8E, 16, FF, 00, 00, 00, 00, A6, B9, 22, 38, AB, 64, 00...
 
[+]

Entropy:
6.9776

Code size:
351.5 KB (359,936 bytes)

Service
Display name:
Install Service(ToolrainDL)

Service name:
ToolrainDL

Description:
To ensure browser softwareinstallation is completed.This service uninstallsitself after browsersoftware installed.

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove chrlike.exe - Powered by Reason Core Security