chromium.exe

Chromium

Luhong Han

The application chromium.exe by Luhong Han has been detected as a potentially unwanted program by 1 anti-malware scanner with very strong indications that the file is a potential threat. It runs as a separate (within the context of its own process) windows Service named “Protect Service(ChromiumP)”.
Publisher:
Luhong Han  (signed and verified)

Product:
Chromium

Version:
1.0.0.1

MD5:
f39bc34365bbc91007b7cff152fc6195

SHA-1:
cd960ae6349f2bcfa89a197ca729aa5298042b60

SHA-256:
1a9b61322af4dff22e342fa5de84b727c7da2d688f6f979c12162a7e24ad1c26

Scanner detections:
1 / 68

Status:
Potentially unwanted

Analysis date:
11/9/2024 1:08:03 AM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
Adware.Elex (M)
16.7.12.10

File size:
408.9 KB (418,688 bytes)

Product version:
51.0.2704.68

Copyright:
Copyright (C) 2016 Chromium Authors

File type:
Executable application (Win32 EXE)

Language:
English (United States)

Common path:
C:\ProgramData\chromium\chromium.exe

Digital Signature
Signed by:

Authority:
thawte, Inc.

Valid from:
7/6/2016 2:00:00 AM

Valid to:
4/2/2017 1:59:59 AM

Subject:
CN=Luhong Han, OU=Individual Developer, O=No Organization Affiliation, L=Beijing, S=Beijing, C=CN

Issuer:
CN=thawte SHA256 Code Signing CA, O="thawte, Inc.", C=US

Serial number:
45B88C5A9972CD2024BB24DB574E2B3C

File PE Metadata
Compilation timestamp:
7/7/2016 11:07:01 AM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
14.0

CTPH (ssdeep):
12288:NttCz0chovHkqqijC2p772WgAa43QDUx/nd:NQhho/xO2l72cJCUpnd

Entry address:
0x2C5F7

Entry point:
98, 51, 62, 00, 00, AB, F0, A3, 95, DB, 81, 67, 34, 8E, 2E, 00, F5, 0F, 84, 39, E3, 29, 00, 00, 00, 00, 33, 7B, 21, 1C, 2B, D6, 8F, 79, 2F, B0, B3, 0D, 0E, DB, 4B, 00, 00, 00, 00, A9, 3A, 66, 7C, 76, 0E, 24, 72, 11, 26, 0A, E3, 0C, F5, AA, D1, E1, 7B, 62, 00, 71, B5, 0D, 95, 51, 82, 85, 35, A1, 95, DB, 81, BD, FD, 18, 9E, 40, DD, 00, 00, 00, 00, D6, BD, 12, 14, A2, 5F, 00, 00, 00, 00, D0, 2E, 24, 72, 69, 14, 79, 66, 77, 28, 15, F9, 75, E1, CC, DF, FE, 61, 1B, 00, 17, BB, 12, F9, 38, 9A, DB, 0B, BE, B7, 18...
 
[+]

Code size:
301 KB (308,224 bytes)

Service
Display name:
Protect Service(ChromiumP)

Service name:
ChromiumP

Description:
To ensure your Chromium software integrity. If this service is disabled or stopped, your Chromium software will not be kept integrity check. This service uninstalls itself when there is no Chromium so

Type:
Win32OwnProcess

Depends on:
RpcSs


Remove chromium.exe - Powered by Reason Core Security