edhelper64.exe

Desk 365

Taiwan Shui Mu Chih Ching Technology Limited

The application edhelper64.exe, “Desk 365 helper application” by Taiwan Shui Mu Chih Ching Technology Limited has been detected as adware by 1 anti-malware scanner with very strong indications that the file is a potential threat.
Publisher:
Taiwan Shui Mu Chih Ching Technology Limited.  (signed by Taiwan Shui Mu Chih Ching Technology Limited)

Product:
Desk 365

Description:
Desk 365 helper application

Version:
1.1.8.6315

MD5:
6f7e240884c220d4b222916d1189dabf

SHA-1:
e8591813d4cad17a87f36641bf024109e5069bb2

SHA-256:
c3cae6b21cbe01a30e438798195654e039da16b9a3b0638f8f924432a9d3df05

Scanner detections:
1 / 68

Status:
Adware

Note:
Our current pool of anti-malware engines have not currently detected this file, however based on our own detection heuristics we feel that this file is unwanted.

Analysis date:
12/25/2024 3:34:26 PM UTC  (today)

Scan engine
Detection
Engine version

Reason Heuristics
PUP.Thinknice (M)
17.2.3.5

File size:
189.2 KB (193,704 bytes)

Product version:
1.1.8.6315

Copyright:
Copyright (C) 2012

Original file name:
edhelper.exe

File type:
Executable application (Win64 EXE)

Language:
English (United States)

Common path:
C:\users\{user}\deskplus\edhelper64.exe

Digital Signature
Authority:
GlobalSign nv-sa

Valid from:
3/13/2013 4:15:13 AM

Valid to:
3/14/2014 4:15:13 AM

Subject:
CN=Taiwan Shui Mu Chih Ching Technology Limited, O=Taiwan Shui Mu Chih Ching Technology Limited, L=新北, S=台湾, C=TW

Issuer:
CN=GlobalSign CodeSigning CA - G2, O=GlobalSign nv-sa, C=BE

Serial number:
1121243D90C81CD8FEC70E99813154FB6459

File PE Metadata
Compilation timestamp:
3/27/2013 8:05:02 AM

OS version:
5.2

OS bitness:
Win64

Subsystem:
Windows GUI

Linker version:
10.0

Entry address:
0x47BC

Entry point:
48, 83, EC, 28, E8, 3B, 2F, 00, 00, 48, 83, C4, 28, E9, 52, FE, FF, FF, CC, CC, 48, 85, C9, 74, 37, 53, 48, 83, EC, 20, 4C, 8B, C1, 48, 8B, 0D, 5C, E7, 00, 00, 33, D2, FF, 15, 7C, 79, 00, 00, 85, C0, 75, 17, E8, 5B, 07, 00, 00, 48, 8B, D8, FF, 15, 62, 78, 00, 00, 8B, C8, E8, 03, 07, 00, 00, 89, 03, 48, 83, C4, 20, 5B, C3, CC, CC, CC, CC, CC, CC, CC, CC, CC, 66, 66, 0F, 1F, 84, 00, 00, 00, 00, 00, 48, 8B, C1, 49, 83, F8, 08, 72, 53, 0F, B6, D2, 49, B9, 01, 01, 01, 01, 01, 01, 01, 01, 49, 0F, AF, D1, 49, 83...
 
[+]

Code size:
41.5 KB (42,496 bytes)

Remove edhelper64.exe - Powered by Reason Core Security